The problem of SessionMiddleware always overwriting cookies.
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 35/100
Direzione di ricerca
Inizia con SessionMiddleware e il percorso sessionCookie mostrato nel report, riproducendo il comportamento con VaultSessionExample. Confronta gli header della risposta prodotti da putHeaders con quelli prodotti da addCookie, quindi verifica che un OtherCookie esistente e l'id della sessione siano entrambi mantenuti negli header Set-Cookie finali.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Hi there 👋
If another cookie is set using methods such as addCookie while SessionMiddleware is in use, it will be overwritten by SessionMiddleware.
When tried with VaultSessionExample.
def app[F[_]: Sync](key: Key[PageViews]): HttpRoutes[F] = {
val dsl = new Http4sDsl[F] {}; import dsl._
HttpRoutes.of {
...
case GET -> Root / "other" / "cookie" =>
Ok("Burn Other Cookies")
.map(_.addCookie("OtherCookie", "hogehoge"))
.map(res => {
println(res.headers.headers) // List(Content-Type: text/plain; charset=UTF-8, Content-Length: 18, Set-Cookie: OtherCookie=hogehoge)
res
})
...
}
}
Check the value of the header inside the SessionMiddleware.
...
sessionCookie(id).map(response.response.putHeaders(_)).map(res => {
println(response.response.headers.headers) // List(Content-Type: text/plain; charset=UTF-8, Content-Length: 18, Set-Cookie: OtherCookie=hogehoge)
println(res.headers.headers) // List(Content-Type: text/plain; charset=UTF-8, Content-Length: 18, Set-Cookie: id=QiTmr/STABek+iyx+Z4SB7j98GJygDupnTokqr1ioDs=; SameSite=Lax; HttpOnly)
res
})
...
OtherCookie is never burned into the browser's cookie, only the id generated by SessionMiddleware is burned into the browser's cookie.
This is probably due to the fact that a new Set-Cookie has been generated inside SessionMiddleware using the putHeaders method.
As a test, instead of generating a Set-Cookie and updating the header, I was able to update the ResponseCookie value inside SessionMiddleware using the addCookie method to process the update without overwriting other cookie information.
example
def sessionCookie(id: SessionIdentifier): F[ResponseCookie] = {
expiration match {
case ExpirationManagement.Static(maxAge, expires) =>
ResponseCookie(sessionIdentifierName,
id.value,
domain = domain,
httpOnly = httpOnly,
secure = secure,
path = path,
sameSite = sameSite.some,
maxAge = maxAge,
expires = expires
).pure[F]
case e @ ExpirationManagement.Dynamic(fromNow) =>
HttpDate.current[F](Functor[F], e.C).flatMap { now =>
fromNow(now).map { case ExpirationManagement.Static(maxAge, expires) =>
ResponseCookie(sessionIdentifierName,
id.value,
domain = domain,
httpOnly = httpOnly,
secure = secure,
path = path,
sameSite = sameSite.some,
maxAge = maxAge,
expires = expires
)
}
}
}
}
...
sessionCookie(id).map(response.response.addCookie(_)).map(res => {
println(response.response.headers.headers) // List(Content-Type: text/plain; charset=UTF-8, Content-Length: 18, Set-Cookie: OtherCookie=hogehoge)
println(res.headers.headers) // List(Content-Type: text/plain; charset=UTF-8, Content-Length: 18, Set-Cookie: OtherCookie=hogehoge, Set-Cookie: id=Z15hkKuTeO7xSPACYOYn2kq4Krqf0QYDWgYJ7fPKliE=; SameSite=Lax; HttpOnly)
res
})
...
If this solution is acceptable, I will create a pull request.
If I am wrong, I would appreciate it if you could let me know.
Thanks!
- Lingua principale
- Scala
- Stelle
- 7
- Fork
- 4
- Merge medio
- 1g 12h
- PR unite (30g)
- 3
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di http4s/http4s-session
-
VaultKeysToRemove keeps deleting keys in later requestsForse già presa @stasimus l’ha presa 9 giorni fa. Aperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 72/100
http4s/http4s-session#373 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
http4s/http4s-session#145 ·
-
Prior artAperta
Difficoltà 5/5 Più di una settimana Idoneità per principianti 20/100
http4s/http4s-session#5 ·
Tutte le issue di http4s/http4s-session
Issue simili
-
"Show threat" doesn't show the evaluation of the threatForse già presa @Zinkelburger l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
lichess-org/lila#22008 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
C21 publishes `reactivemongo/core/SSL` as Java 23 bytecode — TLS connections fail on any JDK < 23Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
ReactiveMongo/ReactiveMongo#1520 ·
I maintainer di solito rispondono entro 1 giorno
-
module: unknown type: bug/reported
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 78/100
OpenXiangShan/XiangShan#6688 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
disneystreaming/smithy4s#2011 ·
-
lsp-clojure eagerly loads lsp-treemacs/treemacs when clients are registeredForse già presa @jlipworth l’ha presa 1 giorno fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 66/100