ZeusWPI/zauth
Separate "cookie not found" and "invalid cookie" paths.
Aberta
#56 aberto em 18 de nov. de 2020
good first issue
Métricas do repositório
- Stars
- (9 estrelas)
- Métricas de merge de PR
- (Métricas PR pendentes)
Description
Now we just wrap 'cookie problems' in a CookieError but there is a distinct difference between two situations:
- There is no cookie with a given name (the cookie was never set, or has expired). This situation is normal and would require the user to login again or restart the oauth flow. This should be a user friendly error.
- There is a cookie, but we can't deserialize it. This is not normal and is probably a development problem, because we are the one serializing the cookie and because they are encrypted and authenticated, users are not able to tamper with them. This should be an internal server error.
The work here will have to be done in ephermeral/cookieable.rs and errors.rs.