Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Cookie is always generated without using withAttribute when using VaultSessionMiddleware.

Aperta
#145 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
45/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Ferma
Stack tecnologico
scala
Ambito
backend

Direzione di ricerca

Inizia con il flusso di VaultSessionMiddleware e la route VaultSessionExample descritti nella issue, quindi esamina la gestione degli attributi di EmberServer collegata in ServerHelpers.scala. Riproduci il caso /context/not/empty e traccia il modo in cui ContextResponse e gli attributi della risposta determinano la generazione dei cookie. Il lavoro è completato quando il comportamento è coperto da un test di regressione e i cookie vengono generati solo quando gli attributi di sessione sono impostati o reimpostati esplicitamente.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Hi there 👋

When EmberServer is used, Request attributes will never be empty.

This is because EmberServer stores connection and other information in attributes by default.

Corresponding code

Also, it is not possible to explicitly change the conditional branching of whether connection information is stored in attributes by default.

This means that whenever unixSocket is not used, there will always be a value for attributes.

I checked what the attributes look like when using VaultSessionMiddleware as a test.

  def transformRoutes[F[_]: Functor](routes: HttpRoutes[F]): SessionRoutes[F, Option[Vault]] = {
    Kleisli { contextRequest: ContextRequest[F, Option[Vault]] =>
      val initVault = contextRequest.context.fold(contextRequest.req.attributes)(context =>
        Vault.union(context, contextRequest.req.attributes)
      )

      println(contextRequest.context) // None
      println(contextRequest.req.attributes.isEmpty) // false
      println(contextRequest.req.attributes.lookup(Request.Keys.ConnectionInfo)) // Some(Connection(127.0.0.1:8080,127.0.0.1:57720,false))
  ...

What's wrong with this?
Cookies are always generated unless you use something like withAttribute(VaultSessionReset.key, VaultSessionReset) in a Meiji way.

I added the following Route to VaultSessionExample as a test, and a cookie was generated even though I did not set an Attribute in the Response.

case GET -> Root / "context" / "not" / "empty" => Ok("Context not empty")

I think we should only generate cookies if we explicitly set a value for attributes in the response.

The easiest way is to add a conditional branch so that a value is passed to ContextResponse only if Response or Context is empty.

outContext
  .lookup(VaultSessionReset.key)
  .fold(
    outContext
      .lookup(VaultKeysToRemove.key)
      .fold(
        // Adding conditional branching
        if (outContext.isEmpty) {
          ContextResponse(None, resp)
        } else {
          ContextResponse(outContext.some, resp.withAttributes(outContext))
        }
      )(toRemove =>
        ContextResponse(toRemove.l.foldLeft(outContext) { case (v, k) => v.delete(k) }.some,
                        resp.withAttributes(outContext)
        )
      )
  )(reset => ContextResponse(None, resp.withAttributes(outContext)))

If this solution is acceptable, I will create a pull request.
If I am wrong, I would appreciate it if you could let me know.

Thanks!

Lingua principale
Scala
Stelle
7
Fork
4
Merge medio
1g 12h
PR unite (30g)
3

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di http4s/http4s-session

Tutte le issue di http4s/http4s-session

Issue simili

Altre issue su Scala

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.