ZeusWPI/zauth

Separate "cookie not found" and "invalid cookie" paths.

オープン

#56 opened on 2020/11/18

 (0 件のコメント) (0 件のリアクション) (0 人の担当者)Rust (1 件のフォーク)auto 404
good first issue

Repository metrics

Stars
 (9 個のスター)
PR merge metrics
 (PR metrics pending)

説明

Now we just wrap 'cookie problems' in a CookieError but there is a distinct difference between two situations:

  • There is no cookie with a given name (the cookie was never set, or has expired). This situation is normal and would require the user to login again or restart the oauth flow. This should be a user friendly error.
  • There is a cookie, but we can't deserialize it. This is not normal and is probably a development problem, because we are the one serializing the cookie and because they are encrypted and authenticated, users are not able to tamper with them. This should be an internal server error.

The work here will have to be done in ephermeral/cookieable.rs and errors.rs.

コントリビューターガイド