mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-11 15:04:02 +09:00
refactor!: move go-chi/session into Gitea (#39504)
The `gitea.com/go-chi/session` package only exists for Gitea, so it moves into `modules/session` to fix its bugs directly. Fixes the flake in https://github.com/go-gitea/gitea/actions/runs/36726154500/job/109923538400. - Sessions are only written back when changed, so a read-only request can't revert a concurrent change or restore a logged-out session, like https://github.com/go-macaron/session/commit/ae808a4a4660c802965c834299ab08f167effd12 - The session cookie is only set once a session holds data - Every backend refreshes the expiry on load and file sessions are written atomically - Also fix https://github.com/go-gitea/gitea/issues/36176 ## ⚠️ BREAKING ⚠️ * the `mysql`, `postgres`, `couchbase` and `memcache` session providers are removed, use `file`, `db` or `redis` instead * login-related cookies are renamed to `gitea_session` and `gitea_remember`, if you'd like to use the old names, set `COOKIE_NAME` and `COOKIE_REMEMBER_NAME` in app.ini --------- Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
1 parent
bea6fcaa84
commit
cf89ecd887
34 files changed
+913
-981
No files matched your search
@@ -151,7 +151,7 @@ func loadSecurityFrom(rootCfg ConfigProvider) {
|
||||
SecretKey = "!#@FDEWREWR&*("
|
||||
}
|
||||
|
||||
CookieRememberName = sec.Key("COOKIE_REMEMBER_NAME").MustString("gitea_incredible")
|
||||
CookieRememberName = sec.Key("COOKIE_REMEMBER_NAME").MustString("gitea_remember")
|
||||
|
||||
ReverseProxyAuthUser = sec.Key("REVERSE_PROXY_AUTHENTICATION_USER").MustString("X-WEBAUTH-USER")
|
||||
ReverseProxyAuthEmail = sec.Key("REVERSE_PROXY_AUTHENTICATION_EMAIL").MustString("X-WEBAUTH-EMAIL")
|
||||
|
||||
@@ -4,19 +4,17 @@
|
||||
package setting
|
||||
|
||||
import (
|
||||
"cmp"
|
||||
"net/http"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
|
||||
"gitea.dev/modules/json"
|
||||
"gitea.dev/modules/log"
|
||||
"gitea.dev/modules/util"
|
||||
)
|
||||
|
||||
// SessionConfig defines Session settings
|
||||
var SessionConfig = struct {
|
||||
OriginalProvider string
|
||||
Provider string
|
||||
Provider string
|
||||
// Provider configuration, it's corresponding to provider.
|
||||
ProviderConfig string
|
||||
// Cookie name to save session ID. Default is "MacaronSession".
|
||||
@@ -34,7 +32,8 @@ var SessionConfig = struct {
|
||||
// SameSite declares if your cookie should be restricted to a first-party or same-site context. Valid strings are "none", "lax", "strict". Default is "lax"
|
||||
SameSite http.SameSite
|
||||
}{
|
||||
CookieName: "i_like_gitea",
|
||||
Provider: "memory", // the "Install" page doesn't load the [session] config
|
||||
CookieName: "gitea_session",
|
||||
Gclifetime: 86400,
|
||||
Maxlifetime: 86400,
|
||||
SameSite: http.SameSiteLaxMode,
|
||||
@@ -42,7 +41,7 @@ var SessionConfig = struct {
|
||||
|
||||
func loadSessionFrom(rootCfg ConfigProvider) {
|
||||
sec := rootCfg.Section("session")
|
||||
SessionConfig.Provider = sec.Key("PROVIDER").In("file", []string{"memory", "file", "redis", "mysql", "postgres", "couchbase", "memcache", "db"})
|
||||
SessionConfig.Provider = sec.Key("PROVIDER").MustString("file")
|
||||
|
||||
switch SessionConfig.Provider {
|
||||
case "redis":
|
||||
@@ -59,12 +58,12 @@ func loadSessionFrom(rootCfg ConfigProvider) {
|
||||
SessionConfig.ProviderConfig = sec.Key("PROVIDER_CONFIG").String()
|
||||
}
|
||||
|
||||
SessionConfig.CookieName = sec.Key("COOKIE_NAME").MustString("i_like_gitea")
|
||||
// HINT: INSTALL-PAGE-COOKIE-INIT: the cookie system is not properly initialized on the Install page, so there is no CookiePath
|
||||
SessionConfig.CookieName = sec.Key("COOKIE_NAME").MustString("gitea_session")
|
||||
// HINT: INSTALL-PAGE-COOKIE-INIT: the cookie system is not properly initialized on the "Install" page, so there is no CookiePath
|
||||
SessionConfig.CookiePath = util.IfZero(AppSubURL, "/")
|
||||
SessionConfig.Secure = sec.Key("COOKIE_SECURE").MustBool(strings.HasPrefix(strings.ToLower(AppURL), "https://"))
|
||||
SessionConfig.Gclifetime = sec.Key("GC_INTERVAL_TIME").MustInt64(86400)
|
||||
SessionConfig.Maxlifetime = sec.Key("SESSION_LIFE_TIME").MustInt64(86400)
|
||||
SessionConfig.Gclifetime = cmp.Or(max(sec.Key("GC_INTERVAL_TIME").MustInt64(86400), 0), 3600)
|
||||
SessionConfig.Maxlifetime = cmp.Or(max(sec.Key("SESSION_LIFE_TIME").MustInt64(86400), 0), SessionConfig.Gclifetime)
|
||||
SessionConfig.Domain = sec.Key("DOMAIN").String()
|
||||
samesiteString := sec.Key("SAME_SITE").In("lax", []string{"none", "lax", "strict"})
|
||||
switch strings.ToLower(samesiteString) {
|
||||
@@ -75,11 +74,4 @@ func loadSessionFrom(rootCfg ConfigProvider) {
|
||||
default:
|
||||
SessionConfig.SameSite = http.SameSiteLaxMode
|
||||
}
|
||||
shadowConfig, err := json.Marshal(SessionConfig)
|
||||
if err != nil {
|
||||
log.Fatal("Can't shadow session config: %v", err)
|
||||
}
|
||||
SessionConfig.ProviderConfig = string(shadowConfig)
|
||||
SessionConfig.OriginalProvider = SessionConfig.Provider
|
||||
SessionConfig.Provider = "VirtualSession"
|
||||
}
|
||||
@@ -69,7 +69,6 @@ PROVIDER = file
|
||||
|
||||
loadRedisFrom(cfg)
|
||||
loadSessionFrom(cfg)
|
||||
// ProviderConfig is shadowed into a JSON blob at the end of loadSessionFrom
|
||||
assert.Contains(t, SessionConfig.ProviderConfig, tt.wantContain)
|
||||
if tt.wantMissing != "" {
|
||||
assert.NotContains(t, SessionConfig.ProviderConfig, tt.wantMissing)
|
||||
@@ -77,3 +76,14 @@ PROVIDER = file
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestSessionNonPositiveLifetimesUseDefaults(t *testing.T) {
|
||||
defer test.MockVariableValue(&SessionConfig)()
|
||||
for _, lifetime := range []string{"0", "-1"} {
|
||||
cfg, err := NewConfigProviderFromData("[session]\nGC_INTERVAL_TIME = " + lifetime + "\nSESSION_LIFE_TIME = " + lifetime)
|
||||
assert.NoError(t, err)
|
||||
loadSessionFrom(cfg)
|
||||
assert.EqualValues(t, 3600, SessionConfig.Gclifetime)
|
||||
assert.EqualValues(t, 3600, SessionConfig.Maxlifetime)
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user