ZeusWPI/zauth

Separate "cookie not found" and "invalid cookie" paths.

Aperta

#56 aperta il 18 nov 2020

 (0 commenti) (0 reazioni) (0 assegnatari)Rust (1 fork)auto 404
good first issue

Metriche repository

Star
 (9 stelle)
Metriche merge PR
 (Metriche PR in attesa)

Descrizione

Now we just wrap 'cookie problems' in a CookieError but there is a distinct difference between two situations:

  • There is no cookie with a given name (the cookie was never set, or has expired). This situation is normal and would require the user to login again or restart the oauth flow. This should be a user friendly error.
  • There is a cookie, but we can't deserialize it. This is not normal and is probably a development problem, because we are the one serializing the cookie and because they are encrypted and authenticated, users are not able to tamper with them. This should be an internal server error.

The work here will have to be done in ephermeral/cookieable.rs and errors.rs.

Guida contributor