Cookie is always generated without using withAttribute when using VaultSessionMiddleware.
还没有人认领这个 Issue。
评估
调研方向
从 issue 中描述的 VaultSessionMiddleware 流程和 VaultSessionExample 路由开始,然后检查 ServerHelpers.scala 中链接的 EmberServer 属性处理。复现 /context/not/empty 情况,并跟踪 ContextResponse 和响应属性如何决定 cookie 的生成。完成的标准是:该行为由回归测试覆盖,并且只有在显式设置或重置 session 属性时才生成 cookie。
由索引模型根据 Issue 内容生成。
描述
Hi there 👋
When EmberServer is used, Request attributes will never be empty.
This is because EmberServer stores connection and other information in attributes by default.
Corresponding code
- https://github.com/http4s/http4s/blob/series/0.23/ember-server/shared/src/main/scala/org/http4s/ember/server/internal/ServerHelpers.scala#L341
- https://github.com/http4s/http4s/blob/series/0.23/ember-server/shared/src/main/scala/org/http4s/ember/server/internal/ServerHelpers.scala#L502
Also, it is not possible to explicitly change the conditional branching of whether connection information is stored in attributes by default.
This means that whenever unixSocket is not used, there will always be a value for attributes.
I checked what the attributes look like when using VaultSessionMiddleware as a test.
def transformRoutes[F[_]: Functor](routes: HttpRoutes[F]): SessionRoutes[F, Option[Vault]] = {
Kleisli { contextRequest: ContextRequest[F, Option[Vault]] =>
val initVault = contextRequest.context.fold(contextRequest.req.attributes)(context =>
Vault.union(context, contextRequest.req.attributes)
)
println(contextRequest.context) // None
println(contextRequest.req.attributes.isEmpty) // false
println(contextRequest.req.attributes.lookup(Request.Keys.ConnectionInfo)) // Some(Connection(127.0.0.1:8080,127.0.0.1:57720,false))
...
What's wrong with this?
Cookies are always generated unless you use something like withAttribute(VaultSessionReset.key, VaultSessionReset) in a Meiji way.
I added the following Route to VaultSessionExample as a test, and a cookie was generated even though I did not set an Attribute in the Response.
case GET -> Root / "context" / "not" / "empty" => Ok("Context not empty")
I think we should only generate cookies if we explicitly set a value for attributes in the response.
The easiest way is to add a conditional branch so that a value is passed to ContextResponse only if Response or Context is empty.
outContext
.lookup(VaultSessionReset.key)
.fold(
outContext
.lookup(VaultKeysToRemove.key)
.fold(
// Adding conditional branching
if (outContext.isEmpty) {
ContextResponse(None, resp)
} else {
ContextResponse(outContext.some, resp.withAttributes(outContext))
}
)(toRemove =>
ContextResponse(toRemove.l.foldLeft(outContext) { case (v, k) => v.delete(k) }.some,
resp.withAttributes(outContext)
)
)
)(reset => ContextResponse(None, resp.withAttributes(outContext)))
If this solution is acceptable, I will create a pull request.
If I am wrong, I would appreciate it if you could let me know.
Thanks!
- 主要语言
- Scala
- 星标
- 7
- 派生
- 4
- 平均合并
- 1 天 12 小时
- 30 天内合并 PR
- 3
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
http4s/http4s-session 的其他 Issue
-
VaultKeysToRemove keeps deleting keys in later requests可能已有人在做 @stasimus 于 10 天前认领。 未关闭
难度 3/5 1-2 天 新手友好度 72/100
http4s/http4s-session#373 ·
-
难度 3/5 1-2 天 新手友好度 35/100
http4s/http4s-session#144 ·
-
Prior art未关闭
难度 5/5 一周以上 新手友好度 20/100
http4s/http4s-session#5 ·
查看 http4s/http4s-session 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
Fix Math.ceilDiv wrong result for exact positive divisions可能已有人在做 @pamod-madubashana 今天认领。 未关闭
难度 2/5 1-3 小时 新手友好度 88/100
scala-native/scala-native#5094 ·
维护者通常 1 天内回复
-
"Show threat" doesn't show the evaluation of the threat可能已有人在做 @Zinkelburger 于 1 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 62/100
lichess-org/lila#22008 · 2 条评论 ·
维护者通常 1 天内回复
-
C21 publishes `reactivemongo/core/SSL` as Java 23 bytecode — TLS connections fail on any JDK < 23未关闭
难度 2/5 1-3 小时 新手友好度 74/100
ReactiveMongo/ReactiveMongo#1520 ·
维护者通常 1 天内回复
-
module: memory type: bug/reported
难度 1/5 1 小时以内 新手友好度 78/100
OpenXiangShan/XiangShan#6688 · 2 条评论 ·
维护者通常 2 天内回复