internal/httpd/logincookie_test.go

v1.43.1
gitbay/internal/httpd/logincookie_test.go history · blame · raw

62 lines · 1987 bytes

 1package httpd
 2
 3import (
 4	"net/http"
 5	"net/http/httptest"
 6	"testing"
 7
 8	"gitbay.org/gitbay/internal/config"
 9	"gitbay.org/gitbay/internal/store"
10)
11
12// The session cookie must be Lax, not Strict. A login link clicked in a mail
13// client is a cross-site top-level navigation, and Strict can withhold the
14// cookie through the redirect that follows, so the visitor lands logged out
15// (#155). Cross-site POSTs stay protected: Lax withholds the cookie from them,
16// and checkOrigin refuses them besides.
17//
18// The other two attributes are what keep the token out of a script's reach
19// and off the wire in clear, so they are asserted on the same literal login
20// hands to http.SetCookie.
21func TestSessionCookieAttributes(t *testing.T) {
22	if sessionSameSite != http.SameSiteLaxMode {
23		t.Errorf("sessionSameSite = %v, want Lax", sessionSameSite)
24	}
25	for _, tls := range []string{"acme", "off"} {
26		s := &Server{cfg: config.Config{}}
27		s.cfg.HTTP.TLS = tls
28		c := s.sessionCookieFor("tok")
29
30		if c.SameSite != http.SameSiteLaxMode {
31			t.Errorf("tls=%s: SameSite = %v, want Lax", tls, c.SameSite)
32		}
33		if !c.HttpOnly {
34			t.Errorf("tls=%s: session cookie is not HttpOnly", tls)
35		}
36		if want := tls != "off"; c.Secure != want {
37			t.Errorf("tls=%s: Secure = %v, want %v", tls, c.Secure, want)
38		}
39	}
40}
41
42// The login link's token rides in the query string — the one
43// documented exception to "never in a URL" — so the response that
44// consumes it must never be cached by an intermediary that might log
45// or replay the URL (#261).
46func TestLoginNoStoreHeader(t *testing.T) {
47	st, err := store.Open(":memory:")
48	if err != nil {
49		t.Fatal(err)
50	}
51	defer st.Close()
52	if err := st.MigrateUp(); err != nil {
53		t.Fatal(err)
54	}
55	s := New(config.Default(), st, nil)
56	rr := httptest.NewRecorder()
57	req := httptest.NewRequest("GET", "/login?token=bogus", nil)
58	s.login(rr, req)
59	if got := rr.Header().Get("Cache-Control"); got != "no-store" {
60		t.Errorf("Cache-Control = %q, want no-store", got)
61	}
62}