Digest session credentials in instrumented fragment keys

This commit is contained in:
GPT on behalf of DHH
2026-10-07 21:45:31 +02:00
parent a95361dd15
commit 105f4b8fd1
2 changed files with 7 additions and 1 deletions
+1 -1
View File
@@ -27,7 +27,7 @@ module CachedResponses
def combined_fragment_cache_key(key)
@fragment_cache_namespace ||= [
@response_cache_version, request.base_url, request.script_name, request.format.to_s, I18n.locale,
Current.user&.id, Current.session&.token,
Current.user&.id, (Digest::SHA256.hexdigest(Current.session.token) if Current.session),
(Digest::SHA256.hexdigest(real_csrf_token) if request.format.html? || request.format.turbo_stream?)
].freeze
super([ @fragment_cache_namespace, key ])
+6
View File
@@ -39,6 +39,8 @@ class FragmentRenderingTest < ActionDispatch::IntegrationTest
end
assert_response :success
assert_not_empty hits
token = users(:david).sessions.order(:id).last.token
assert_not_includes hits.join, token
end
test "disabled page caching retains fresh native fragments after foreign leaf writes" do
@@ -119,12 +121,16 @@ class FragmentRenderingTest < ActionDispatch::IntegrationTest
foreign_write("UPDATE action_text_rich_texts SET body = ? WHERE record_type = 'Message' AND record_id = ?", "foreign broadcast body", @message.id)
FragmentCache.store.expects(:read).never
FragmentCache.store.expects(:write).never
FragmentCache.store.expects(:read_multi).never
FragmentCache.store.expects(:write_multi).never
@message.reload.broadcast_create
assert_rendered_turbo_stream_broadcast @room, :messages, action: "append", target: [ @room, :messages ] do |stream|
assert_includes stream.to_html, "foreign broadcast body"
end
body = ApplicationController.render(partial: "messages/message", locals: { message: @message.reload })
assert_includes body, "foreign broadcast body"
collection = ApplicationController.render(partial: "messages/message", collection: [ @message.reload ], cached: true)
assert_includes collection, "foreign broadcast body"
assert_not ApplicationController.new.perform_caching
end