Cookie is always generated without using withAttribute when using VaultSessionMiddleware.
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 45/100
Direzione di ricerca
Inizia con il flusso di VaultSessionMiddleware e la route VaultSessionExample descritti nella issue, quindi esamina la gestione degli attributi di EmberServer collegata in ServerHelpers.scala. Riproduci il caso /context/not/empty e traccia il modo in cui ContextResponse e gli attributi della risposta determinano la generazione dei cookie. Il lavoro è completato quando il comportamento è coperto da un test di regressione e i cookie vengono generati solo quando gli attributi di sessione sono impostati o reimpostati esplicitamente.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Hi there 👋
When EmberServer is used, Request attributes will never be empty.
This is because EmberServer stores connection and other information in attributes by default.
Corresponding code
- https://github.com/http4s/http4s/blob/series/0.23/ember-server/shared/src/main/scala/org/http4s/ember/server/internal/ServerHelpers.scala#L341
- https://github.com/http4s/http4s/blob/series/0.23/ember-server/shared/src/main/scala/org/http4s/ember/server/internal/ServerHelpers.scala#L502
Also, it is not possible to explicitly change the conditional branching of whether connection information is stored in attributes by default.
This means that whenever unixSocket is not used, there will always be a value for attributes.
I checked what the attributes look like when using VaultSessionMiddleware as a test.
def transformRoutes[F[_]: Functor](routes: HttpRoutes[F]): SessionRoutes[F, Option[Vault]] = {
Kleisli { contextRequest: ContextRequest[F, Option[Vault]] =>
val initVault = contextRequest.context.fold(contextRequest.req.attributes)(context =>
Vault.union(context, contextRequest.req.attributes)
)
println(contextRequest.context) // None
println(contextRequest.req.attributes.isEmpty) // false
println(contextRequest.req.attributes.lookup(Request.Keys.ConnectionInfo)) // Some(Connection(127.0.0.1:8080,127.0.0.1:57720,false))
...
What's wrong with this?
Cookies are always generated unless you use something like withAttribute(VaultSessionReset.key, VaultSessionReset) in a Meiji way.
I added the following Route to VaultSessionExample as a test, and a cookie was generated even though I did not set an Attribute in the Response.
case GET -> Root / "context" / "not" / "empty" => Ok("Context not empty")
I think we should only generate cookies if we explicitly set a value for attributes in the response.
The easiest way is to add a conditional branch so that a value is passed to ContextResponse only if Response or Context is empty.
outContext
.lookup(VaultSessionReset.key)
.fold(
outContext
.lookup(VaultKeysToRemove.key)
.fold(
// Adding conditional branching
if (outContext.isEmpty) {
ContextResponse(None, resp)
} else {
ContextResponse(outContext.some, resp.withAttributes(outContext))
}
)(toRemove =>
ContextResponse(toRemove.l.foldLeft(outContext) { case (v, k) => v.delete(k) }.some,
resp.withAttributes(outContext)
)
)
)(reset => ContextResponse(None, resp.withAttributes(outContext)))
If this solution is acceptable, I will create a pull request.
If I am wrong, I would appreciate it if you could let me know.
Thanks!
- Lingua principale
- Scala
- Stelle
- 7
- Fork
- 4
- Merge medio
- 1g 12h
- PR unite (30g)
- 3
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di http4s/http4s-session
-
VaultKeysToRemove keeps deleting keys in later requestsForse già presa @stasimus l’ha presa 9 giorni fa. Aperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 72/100
http4s/http4s-session#373 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
http4s/http4s-session#144 ·
-
Prior artAperta
Difficoltà 5/5 Più di una settimana Idoneità per principianti 20/100
http4s/http4s-session#5 ·
Tutte le issue di http4s/http4s-session
Issue simili
-
"Show threat" doesn't show the evaluation of the threatForse già presa @Zinkelburger l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
lichess-org/lila#22008 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
C21 publishes `reactivemongo/core/SSL` as Java 23 bytecode — TLS connections fail on any JDK < 23Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
ReactiveMongo/ReactiveMongo#1520 ·
I maintainer di solito rispondono entro 1 giorno
-
module: unknown type: bug/reported
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 78/100
OpenXiangShan/XiangShan#6688 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
disneystreaming/smithy4s#2011 ·
-
bug good first issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 83/100
I maintainer di solito rispondono entro 1 giorno