2008-01-05 08:32:06 -05:00
|
|
|
require 'abstract_unit'
|
2014-12-03 20:05:02 -05:00
|
|
|
require 'openssl'
|
2012-10-30 23:06:46 -04:00
|
|
|
require 'active_support/key_generator'
|
2013-03-24 19:20:24 -04:00
|
|
|
require 'active_support/message_verifier'
|
2004-11-23 20:04:44 -05:00
|
|
|
|
2015-10-01 21:47:13 -04:00
|
|
|
class CookieJarTest < ActiveSupport::TestCase
|
|
|
|
attr_reader :request
|
|
|
|
|
|
|
|
def setup
|
2015-12-01 14:28:01 -05:00
|
|
|
@request = ActionDispatch::Request.empty
|
2015-10-01 21:47:13 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
def test_fetch
|
|
|
|
x = Object.new
|
|
|
|
assert_not request.cookie_jar.key?('zzzzzz')
|
|
|
|
assert_equal x, request.cookie_jar.fetch('zzzzzz', x)
|
|
|
|
assert_not request.cookie_jar.key?('zzzzzz')
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_fetch_exists
|
|
|
|
x = Object.new
|
|
|
|
request.cookie_jar['foo'] = 'bar'
|
|
|
|
assert_equal 'bar', request.cookie_jar.fetch('foo', x)
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_fetch_block
|
|
|
|
x = Object.new
|
|
|
|
assert_not request.cookie_jar.key?('zzzzzz')
|
|
|
|
assert_equal x, request.cookie_jar.fetch('zzzzzz') { x }
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_key_is_to_s
|
|
|
|
request.cookie_jar['foo'] = 'bar'
|
|
|
|
assert_equal 'bar', request.cookie_jar.fetch(:foo)
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_fetch_type_error
|
|
|
|
assert_raises(KeyError) do
|
|
|
|
request.cookie_jar.fetch(:omglolwut)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_each
|
|
|
|
request.cookie_jar['foo'] = :bar
|
|
|
|
list = []
|
|
|
|
request.cookie_jar.each do |k,v|
|
|
|
|
list << [k, v]
|
|
|
|
end
|
|
|
|
|
|
|
|
assert_equal [['foo', :bar]], list
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_enumerable
|
|
|
|
request.cookie_jar['foo'] = :bar
|
|
|
|
actual = request.cookie_jar.map { |k,v| [k.to_s, v.to_s] }
|
|
|
|
assert_equal [['foo', 'bar']], actual
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_key_methods
|
|
|
|
assert !request.cookie_jar.key?(:foo)
|
|
|
|
assert !request.cookie_jar.has_key?("foo")
|
|
|
|
|
|
|
|
request.cookie_jar[:foo] = :bar
|
|
|
|
assert request.cookie_jar.key?(:foo)
|
|
|
|
assert request.cookie_jar.has_key?("foo")
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_write_doesnt_set_a_nil_header
|
|
|
|
headers = {}
|
|
|
|
request.cookie_jar.write(headers)
|
|
|
|
assert !headers.include?('Set-Cookie')
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2010-06-11 05:44:18 -04:00
|
|
|
class CookiesTest < ActionController::TestCase
|
2014-02-05 06:15:11 -05:00
|
|
|
class CustomSerializer
|
|
|
|
def self.load(value)
|
|
|
|
value.to_s + " and loaded"
|
|
|
|
end
|
|
|
|
|
|
|
|
def self.dump(value)
|
|
|
|
value.to_s + " was dumped"
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2004-11-23 20:04:44 -05:00
|
|
|
class TestController < ActionController::Base
|
2004-11-25 21:04:35 -05:00
|
|
|
def authenticate
|
|
|
|
cookies["user_name"] = "david"
|
2009-05-22 19:57:45 -04:00
|
|
|
head :ok
|
2004-11-25 21:04:35 -05:00
|
|
|
end
|
|
|
|
|
2009-02-03 21:37:55 -05:00
|
|
|
def set_with_with_escapable_characters
|
|
|
|
cookies["that & guy"] = "foo & bar => baz"
|
2009-05-22 19:57:45 -04:00
|
|
|
head :ok
|
2009-02-03 21:37:55 -05:00
|
|
|
end
|
|
|
|
|
2007-09-28 10:18:47 -04:00
|
|
|
def authenticate_for_fourteen_days
|
2008-12-21 07:35:29 -05:00
|
|
|
cookies["user_name"] = { "value" => "david", "expires" => Time.utc(2005, 10, 10,5) }
|
2009-05-22 19:57:45 -04:00
|
|
|
head :ok
|
2004-11-25 21:04:35 -05:00
|
|
|
end
|
|
|
|
|
2007-09-28 10:18:47 -04:00
|
|
|
def authenticate_for_fourteen_days_with_symbols
|
2008-12-21 07:35:29 -05:00
|
|
|
cookies[:user_name] = { :value => "david", :expires => Time.utc(2005, 10, 10,5) }
|
2009-05-22 19:57:45 -04:00
|
|
|
head :ok
|
2004-11-25 21:09:38 -05:00
|
|
|
end
|
|
|
|
|
2004-11-25 21:04:35 -05:00
|
|
|
def set_multiple_cookies
|
2008-12-21 07:35:29 -05:00
|
|
|
cookies["user_name"] = { "value" => "david", "expires" => Time.utc(2005, 10, 10,5) }
|
2004-11-25 21:04:35 -05:00
|
|
|
cookies["login"] = "XJ-122"
|
2009-05-22 19:57:45 -04:00
|
|
|
head :ok
|
2004-11-25 21:04:35 -05:00
|
|
|
end
|
2008-12-19 17:35:23 -05:00
|
|
|
|
2005-04-02 03:54:25 -05:00
|
|
|
def access_frozen_cookies
|
2006-09-29 04:04:39 -04:00
|
|
|
cookies["will"] = "work"
|
2009-05-22 19:57:45 -04:00
|
|
|
head :ok
|
2005-04-02 03:54:25 -05:00
|
|
|
end
|
|
|
|
|
2007-01-17 01:51:59 -05:00
|
|
|
def logout
|
|
|
|
cookies.delete("user_name")
|
2009-05-22 19:57:45 -04:00
|
|
|
head :ok
|
2007-01-17 01:51:59 -05:00
|
|
|
end
|
|
|
|
|
2012-04-30 08:32:53 -04:00
|
|
|
alias delete_cookie logout
|
|
|
|
|
2007-07-01 19:27:59 -04:00
|
|
|
def delete_cookie_with_path
|
|
|
|
cookies.delete("user_name", :path => '/beaten')
|
2009-05-22 19:57:45 -04:00
|
|
|
head :ok
|
2007-07-01 19:27:59 -04:00
|
|
|
end
|
|
|
|
|
2007-09-21 11:05:49 -04:00
|
|
|
def authenticate_with_http_only
|
2009-02-07 16:37:54 -05:00
|
|
|
cookies["user_name"] = { :value => "david", :httponly => true }
|
2009-05-22 19:57:45 -04:00
|
|
|
head :ok
|
2007-01-17 01:51:59 -05:00
|
|
|
end
|
2010-09-22 15:03:39 -04:00
|
|
|
|
2010-09-13 17:29:25 -04:00
|
|
|
def authenticate_with_secure
|
|
|
|
cookies["user_name"] = { :value => "david", :secure => true }
|
|
|
|
head :ok
|
|
|
|
end
|
2009-12-20 17:33:13 -05:00
|
|
|
|
|
|
|
def set_permanent_cookie
|
|
|
|
cookies.permanent[:user_name] = "Jamie"
|
|
|
|
head :ok
|
|
|
|
end
|
2010-01-16 18:21:46 -05:00
|
|
|
|
2009-12-20 17:33:13 -05:00
|
|
|
def set_signed_cookie
|
|
|
|
cookies.signed[:user_id] = 45
|
|
|
|
head :ok
|
|
|
|
end
|
2010-01-16 18:21:46 -05:00
|
|
|
|
2013-03-24 19:20:24 -04:00
|
|
|
def get_signed_cookie
|
|
|
|
cookies.signed[:user_id]
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
2012-10-30 14:41:11 -04:00
|
|
|
def set_encrypted_cookie
|
|
|
|
cookies.encrypted[:foo] = 'bar'
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
2015-10-01 21:47:13 -04:00
|
|
|
class JSONWrapper
|
|
|
|
def initialize(obj)
|
|
|
|
@obj = obj
|
|
|
|
end
|
|
|
|
|
|
|
|
def as_json(options = nil)
|
|
|
|
"wrapped: #{@obj.as_json(options)}"
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def set_wrapped_signed_cookie
|
|
|
|
cookies.signed[:user_id] = JSONWrapper.new(45)
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
2014-08-17 15:40:24 -04:00
|
|
|
def set_wrapped_encrypted_cookie
|
|
|
|
cookies.encrypted[:foo] = JSONWrapper.new('bar')
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
2013-03-28 15:35:48 -04:00
|
|
|
def get_encrypted_cookie
|
|
|
|
cookies.encrypted[:foo]
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
2013-02-19 07:35:03 -05:00
|
|
|
def set_invalid_encrypted_cookie
|
|
|
|
cookies[:invalid_cookie] = 'invalid--9170e00a57cfc27083363b5c75b835e477bd90cf'
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
2010-05-17 19:43:06 -04:00
|
|
|
def raise_data_overflow
|
|
|
|
cookies.signed[:foo] = 'bye!' * 1024
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
|
|
|
def tampered_cookies
|
|
|
|
cookies[:tampered] = "BAh7BjoIZm9vIghiYXI%3D--123456780"
|
|
|
|
cookies.signed[:tampered]
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
2009-12-20 17:33:13 -05:00
|
|
|
def set_permanent_signed_cookie
|
|
|
|
cookies.permanent.signed[:remember_me] = 100
|
|
|
|
head :ok
|
|
|
|
end
|
2010-03-17 20:15:52 -04:00
|
|
|
|
|
|
|
def delete_and_set_cookie
|
|
|
|
cookies.delete :user_name
|
|
|
|
cookies[:user_name] = { :value => "david", :expires => Time.utc(2005, 10, 10,5) }
|
|
|
|
head :ok
|
|
|
|
end
|
2010-06-11 06:00:35 -04:00
|
|
|
|
|
|
|
def set_cookie_with_domain
|
|
|
|
cookies[:user_name] = {:value => "rizwanreza", :domain => :all}
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
2014-11-26 16:34:52 -05:00
|
|
|
def set_cookie_with_domain_all_as_string
|
|
|
|
cookies[:user_name] = {:value => "rizwanreza", :domain => 'all'}
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
2010-06-11 06:00:35 -04:00
|
|
|
def delete_cookie_with_domain
|
|
|
|
cookies.delete(:user_name, :domain => :all)
|
|
|
|
head :ok
|
|
|
|
end
|
2010-10-13 14:58:25 -04:00
|
|
|
|
2014-11-26 16:34:52 -05:00
|
|
|
def delete_cookie_with_domain_all_as_string
|
|
|
|
cookies.delete(:user_name, :domain => 'all')
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
2011-01-21 06:59:49 -05:00
|
|
|
def set_cookie_with_domain_and_tld
|
|
|
|
cookies[:user_name] = {:value => "rizwanreza", :domain => :all, :tld_length => 2}
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
|
|
|
def delete_cookie_with_domain_and_tld
|
|
|
|
cookies.delete(:user_name, :domain => :all, :tld_length => 2)
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
2011-01-21 06:58:33 -05:00
|
|
|
def set_cookie_with_domains
|
|
|
|
cookies[:user_name] = {:value => "rizwanreza", :domain => %w(example1.com example2.com .example3.com)}
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
|
|
|
def delete_cookie_with_domains
|
|
|
|
cookies.delete(:user_name, :domain => %w(example1.com example2.com .example3.com))
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
2010-10-13 14:58:25 -04:00
|
|
|
def symbol_key
|
|
|
|
cookies[:user_name] = "david"
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
|
|
|
def string_key
|
2011-05-19 10:33:18 -04:00
|
|
|
cookies['user_name'] = "dhh"
|
2010-10-13 14:58:25 -04:00
|
|
|
head :ok
|
|
|
|
end
|
2011-03-06 07:49:44 -05:00
|
|
|
|
|
|
|
def symbol_key_mock
|
|
|
|
cookies[:user_name] = "david" if cookies[:user_name] == "andrew"
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
|
|
|
def string_key_mock
|
|
|
|
cookies['user_name'] = "david" if cookies['user_name'] == "andrew"
|
|
|
|
head :ok
|
|
|
|
end
|
|
|
|
|
|
|
|
def noop
|
|
|
|
head :ok
|
|
|
|
end
|
2004-11-23 20:04:44 -05:00
|
|
|
end
|
|
|
|
|
2009-01-07 16:23:10 -05:00
|
|
|
tests TestController
|
2004-11-23 20:04:44 -05:00
|
|
|
|
2015-10-01 21:47:13 -04:00
|
|
|
SALT = 'b3c631c314c0bbca50c1b2843150fe33'
|
|
|
|
|
2009-01-07 16:23:10 -05:00
|
|
|
def setup
|
2009-04-08 20:33:06 -04:00
|
|
|
super
|
2013-01-27 17:17:56 -05:00
|
|
|
|
2015-10-01 21:47:13 -04:00
|
|
|
@request.env["action_dispatch.key_generator"] = ActiveSupport::KeyGenerator.new(SALT, iterations: 2)
|
2013-01-27 17:17:56 -05:00
|
|
|
|
2015-10-01 21:47:13 -04:00
|
|
|
@request.env["action_dispatch.signed_cookie_salt"] =
|
|
|
|
@request.env["action_dispatch.encrypted_cookie_salt"] =
|
|
|
|
@request.env["action_dispatch.encrypted_signed_cookie_salt"] = SALT
|
2013-01-27 17:17:56 -05:00
|
|
|
|
2015-10-01 21:47:13 -04:00
|
|
|
@request.host = "www.nextangle.com"
|
2011-06-30 07:01:26 -04:00
|
|
|
end
|
|
|
|
|
2004-11-23 20:04:44 -05:00
|
|
|
def test_setting_cookie
|
2007-01-17 01:51:59 -05:00
|
|
|
get :authenticate
|
2009-05-22 19:57:45 -04:00
|
|
|
assert_cookie_header "user_name=david; path=/"
|
2008-12-20 22:25:09 -05:00
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
2004-11-23 20:04:44 -05:00
|
|
|
end
|
|
|
|
|
2012-04-30 08:55:06 -04:00
|
|
|
def test_setting_the_same_value_to_cookie
|
|
|
|
request.cookies[:user_name] = 'david'
|
|
|
|
get :authenticate
|
2015-06-27 10:38:45 -04:00
|
|
|
assert_predicate response.cookies, :empty?
|
2012-04-30 08:55:06 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
def test_setting_the_same_value_to_permanent_cookie
|
|
|
|
request.cookies[:user_name] = 'Jamie'
|
|
|
|
get :set_permanent_cookie
|
2014-08-18 02:29:21 -04:00
|
|
|
assert_equal({'user_name' => 'Jamie'}, response.cookies)
|
2012-04-30 08:55:06 -04:00
|
|
|
end
|
|
|
|
|
2009-02-03 21:37:55 -05:00
|
|
|
def test_setting_with_escapable_characters
|
|
|
|
get :set_with_with_escapable_characters
|
2009-05-22 19:57:45 -04:00
|
|
|
assert_cookie_header "that+%26+guy=foo+%26+bar+%3D%3E+baz; path=/"
|
2009-02-03 21:37:55 -05:00
|
|
|
assert_equal({"that & guy" => "foo & bar => baz"}, @response.cookies)
|
|
|
|
end
|
|
|
|
|
2004-11-25 21:04:35 -05:00
|
|
|
def test_setting_cookie_for_fourteen_days
|
2007-09-28 10:18:47 -04:00
|
|
|
get :authenticate_for_fourteen_days
|
2013-01-10 22:34:52 -05:00
|
|
|
assert_cookie_header "user_name=david; path=/; expires=Mon, 10 Oct 2005 05:00:00 -0000"
|
2008-12-20 22:25:09 -05:00
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
2008-12-19 18:15:22 -05:00
|
|
|
end
|
2004-11-25 21:04:35 -05:00
|
|
|
|
2004-11-25 21:09:38 -05:00
|
|
|
def test_setting_cookie_for_fourteen_days_with_symbols
|
2008-07-17 13:19:09 -04:00
|
|
|
get :authenticate_for_fourteen_days_with_symbols
|
2013-01-10 22:34:52 -05:00
|
|
|
assert_cookie_header "user_name=david; path=/; expires=Mon, 10 Oct 2005 05:00:00 -0000"
|
2008-12-20 22:25:09 -05:00
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
2004-11-25 21:09:38 -05:00
|
|
|
end
|
|
|
|
|
2007-09-21 11:05:49 -04:00
|
|
|
def test_setting_cookie_with_http_only
|
|
|
|
get :authenticate_with_http_only
|
2009-05-22 19:57:45 -04:00
|
|
|
assert_cookie_header "user_name=david; path=/; HttpOnly"
|
2008-12-20 22:25:09 -05:00
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
2008-12-19 18:15:22 -05:00
|
|
|
end
|
2010-09-22 15:03:39 -04:00
|
|
|
|
2010-09-13 17:29:25 -04:00
|
|
|
def test_setting_cookie_with_secure
|
2010-10-22 10:34:45 -04:00
|
|
|
@request.env["HTTPS"] = "on"
|
2010-09-13 17:29:25 -04:00
|
|
|
get :authenticate_with_secure
|
|
|
|
assert_cookie_header "user_name=david; path=/; secure"
|
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
|
|
|
end
|
2007-09-21 11:05:49 -04:00
|
|
|
|
2011-11-23 15:36:56 -05:00
|
|
|
def test_setting_cookie_with_secure_when_always_write_cookie_is_true
|
2015-08-21 16:33:50 -04:00
|
|
|
old_cookie, @request.cookie_jar.always_write_cookie = @request.cookie_jar.always_write_cookie, true
|
2010-10-22 10:34:45 -04:00
|
|
|
get :authenticate_with_secure
|
|
|
|
assert_cookie_header "user_name=david; path=/; secure"
|
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
2015-08-21 16:33:50 -04:00
|
|
|
ensure
|
|
|
|
@request.cookie_jar.always_write_cookie = old_cookie
|
2010-10-22 10:34:45 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
def test_not_setting_cookie_with_secure
|
|
|
|
get :authenticate_with_secure
|
|
|
|
assert_not_cookie_header "user_name=david; path=/; secure"
|
|
|
|
assert_not_equal({"user_name" => "david"}, @response.cookies)
|
|
|
|
end
|
|
|
|
|
2004-11-25 21:04:35 -05:00
|
|
|
def test_multiple_cookies
|
2007-01-17 01:51:59 -05:00
|
|
|
get :set_multiple_cookies
|
|
|
|
assert_equal 2, @response.cookies.size
|
2013-01-10 22:34:52 -05:00
|
|
|
assert_cookie_header "user_name=david; path=/; expires=Mon, 10 Oct 2005 05:00:00 -0000\nlogin=XJ-122; path=/"
|
2008-12-20 22:25:09 -05:00
|
|
|
assert_equal({"login" => "XJ-122", "user_name" => "david"}, @response.cookies)
|
2008-12-19 18:15:22 -05:00
|
|
|
end
|
2004-11-25 21:04:35 -05:00
|
|
|
|
2005-04-02 03:54:25 -05:00
|
|
|
def test_setting_test_cookie
|
2007-01-17 01:51:59 -05:00
|
|
|
assert_nothing_raised { get :access_frozen_cookies }
|
|
|
|
end
|
2008-12-19 17:35:23 -05:00
|
|
|
|
2007-01-17 01:51:59 -05:00
|
|
|
def test_expiring_cookie
|
2012-04-30 08:32:53 -04:00
|
|
|
request.cookies[:user_name] = 'Joe'
|
2007-01-17 01:51:59 -05:00
|
|
|
get :logout
|
2013-01-10 22:34:52 -05:00
|
|
|
assert_cookie_header "user_name=; path=/; max-age=0; expires=Thu, 01 Jan 1970 00:00:00 -0000"
|
2008-12-20 22:25:09 -05:00
|
|
|
assert_equal({"user_name" => nil}, @response.cookies)
|
2008-12-19 18:15:22 -05:00
|
|
|
end
|
2008-12-19 17:35:23 -05:00
|
|
|
|
2007-07-01 19:27:59 -04:00
|
|
|
def test_delete_cookie_with_path
|
2012-04-30 08:32:53 -04:00
|
|
|
request.cookies[:user_name] = 'Joe'
|
2007-07-01 19:27:59 -04:00
|
|
|
get :delete_cookie_with_path
|
2013-01-10 22:34:52 -05:00
|
|
|
assert_cookie_header "user_name=; path=/beaten; max-age=0; expires=Thu, 01 Jan 1970 00:00:00 -0000"
|
2008-05-12 18:25:56 -04:00
|
|
|
end
|
2009-05-22 19:57:45 -04:00
|
|
|
|
2012-04-30 08:32:53 -04:00
|
|
|
def test_delete_unexisting_cookie
|
|
|
|
request.cookies.clear
|
|
|
|
get :delete_cookie
|
2015-06-27 10:38:45 -04:00
|
|
|
assert_predicate @response.cookies, :empty?
|
2012-04-30 08:32:53 -04:00
|
|
|
end
|
|
|
|
|
2012-01-23 08:10:43 -05:00
|
|
|
def test_deleted_cookie_predicate
|
2012-04-30 08:32:53 -04:00
|
|
|
cookies[:user_name] = 'Joe'
|
2012-01-23 08:10:43 -05:00
|
|
|
cookies.delete("user_name")
|
|
|
|
assert cookies.deleted?("user_name")
|
|
|
|
assert_equal false, cookies.deleted?("another")
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_deleted_cookie_predicate_with_mismatching_options
|
2012-04-30 08:32:53 -04:00
|
|
|
cookies[:user_name] = 'Joe'
|
2012-01-23 08:10:43 -05:00
|
|
|
cookies.delete("user_name", :path => "/path")
|
|
|
|
assert_equal false, cookies.deleted?("user_name", :path => "/different")
|
|
|
|
end
|
|
|
|
|
2009-05-28 10:18:27 -04:00
|
|
|
def test_cookies_persist_throughout_request
|
2009-10-26 21:01:09 -04:00
|
|
|
response = get :authenticate
|
2015-06-27 10:38:45 -04:00
|
|
|
assert_match(/user_name=david/, response.headers["Set-Cookie"])
|
2009-05-28 10:18:27 -04:00
|
|
|
end
|
2009-12-20 17:33:13 -05:00
|
|
|
|
2013-04-02 19:20:24 -04:00
|
|
|
def test_set_permanent_cookie
|
2009-12-20 17:33:13 -05:00
|
|
|
get :set_permanent_cookie
|
2010-09-22 15:03:39 -04:00
|
|
|
assert_match(/Jamie/, @response.headers["Set-Cookie"])
|
|
|
|
assert_match(%r(#{20.years.from_now.utc.year}), @response.headers["Set-Cookie"])
|
2009-12-20 17:33:13 -05:00
|
|
|
end
|
2010-01-16 18:21:46 -05:00
|
|
|
|
2013-04-02 19:20:24 -04:00
|
|
|
def test_read_permanent_cookie
|
|
|
|
get :set_permanent_cookie
|
|
|
|
assert_equal 'Jamie', @controller.send(:cookies).permanent[:user_name]
|
|
|
|
end
|
|
|
|
|
2014-08-12 15:57:51 -04:00
|
|
|
def test_signed_cookie_using_default_digest
|
|
|
|
get :set_signed_cookie
|
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 45, cookies[:user_id]
|
|
|
|
assert_equal 45, cookies.signed[:user_id]
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
signed_cookie_salt = @request.env["action_dispatch.signed_cookie_salt"]
|
|
|
|
secret = key_generator.generate_key(signed_cookie_salt)
|
|
|
|
|
|
|
|
verifier = ActiveSupport::MessageVerifier.new(secret, serializer: Marshal, digest: 'SHA1')
|
|
|
|
assert_equal verifier.generate(45), cookies[:user_id]
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_signed_cookie_using_custom_digest
|
|
|
|
@request.env["action_dispatch.cookies_digest"] = 'SHA256'
|
|
|
|
get :set_signed_cookie
|
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 45, cookies[:user_id]
|
|
|
|
assert_equal 45, cookies.signed[:user_id]
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
signed_cookie_salt = @request.env["action_dispatch.signed_cookie_salt"]
|
|
|
|
secret = key_generator.generate_key(signed_cookie_salt)
|
|
|
|
|
|
|
|
verifier = ActiveSupport::MessageVerifier.new(secret, serializer: Marshal, digest: 'SHA256')
|
|
|
|
assert_equal verifier.generate(45), cookies[:user_id]
|
|
|
|
end
|
|
|
|
|
2014-02-05 06:15:11 -05:00
|
|
|
def test_signed_cookie_using_default_serializer
|
|
|
|
get :set_signed_cookie
|
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 45, cookies[:user_id]
|
|
|
|
assert_equal 45, cookies.signed[:user_id]
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_signed_cookie_using_marshal_serializer
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :marshal
|
|
|
|
get :set_signed_cookie
|
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 45, cookies[:user_id]
|
|
|
|
assert_equal 45, cookies.signed[:user_id]
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_signed_cookie_using_json_serializer
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :json
|
|
|
|
get :set_signed_cookie
|
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 45, cookies[:user_id]
|
|
|
|
assert_equal 45, cookies.signed[:user_id]
|
|
|
|
end
|
|
|
|
|
2014-08-17 15:40:24 -04:00
|
|
|
def test_wrapped_signed_cookie_using_json_serializer
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :json
|
|
|
|
get :set_wrapped_signed_cookie
|
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 'wrapped: 45', cookies[:user_id]
|
|
|
|
assert_equal 'wrapped: 45', cookies.signed[:user_id]
|
|
|
|
end
|
|
|
|
|
2014-02-05 06:15:11 -05:00
|
|
|
def test_signed_cookie_using_custom_serializer
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = CustomSerializer
|
|
|
|
get :set_signed_cookie
|
|
|
|
assert_not_equal 45, cookies[:user_id]
|
|
|
|
assert_equal '45 was dumped and loaded', cookies.signed[:user_id]
|
|
|
|
end
|
|
|
|
|
2014-02-08 14:28:53 -05:00
|
|
|
def test_signed_cookie_using_hybrid_serializer_can_migrate_marshal_dumped_value_to_json
|
2014-02-07 22:23:06 -05:00
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :hybrid
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
signed_cookie_salt = @request.env["action_dispatch.signed_cookie_salt"]
|
|
|
|
secret = key_generator.generate_key(signed_cookie_salt)
|
2014-02-08 14:28:53 -05:00
|
|
|
|
|
|
|
marshal_value = ActiveSupport::MessageVerifier.new(secret, serializer: Marshal).generate(45)
|
|
|
|
@request.headers["Cookie"] = "user_id=#{marshal_value}"
|
2014-02-07 22:23:06 -05:00
|
|
|
|
|
|
|
get :get_signed_cookie
|
|
|
|
|
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 45, cookies[:user_id]
|
|
|
|
assert_equal 45, cookies.signed[:user_id]
|
2014-02-08 14:28:53 -05:00
|
|
|
|
2014-02-09 04:12:11 -05:00
|
|
|
verifier = ActiveSupport::MessageVerifier.new(secret, serializer: JSON)
|
|
|
|
assert_equal 45, verifier.verify(@response.cookies['user_id'])
|
2014-02-07 22:23:06 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
def test_signed_cookie_using_hybrid_serializer_can_read_from_json_dumped_value
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :hybrid
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
signed_cookie_salt = @request.env["action_dispatch.signed_cookie_salt"]
|
|
|
|
secret = key_generator.generate_key(signed_cookie_salt)
|
2014-02-08 14:28:53 -05:00
|
|
|
json_value = ActiveSupport::MessageVerifier.new(secret, serializer: JSON).generate(45)
|
|
|
|
@request.headers["Cookie"] = "user_id=#{json_value}"
|
2014-02-07 22:23:06 -05:00
|
|
|
|
|
|
|
get :get_signed_cookie
|
|
|
|
|
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 45, cookies[:user_id]
|
|
|
|
assert_equal 45, cookies.signed[:user_id]
|
2014-02-09 04:12:11 -05:00
|
|
|
|
|
|
|
assert_nil @response.cookies["user_id"]
|
2014-02-07 22:23:06 -05:00
|
|
|
end
|
|
|
|
|
2014-12-02 19:19:10 -05:00
|
|
|
def test_accessing_nonexistent_signed_cookie_should_not_raise_an_invalid_signature
|
2013-02-19 07:35:03 -05:00
|
|
|
get :set_signed_cookie
|
|
|
|
assert_nil @controller.send(:cookies).signed[:non_existant_attribute]
|
|
|
|
end
|
|
|
|
|
2014-02-05 06:15:11 -05:00
|
|
|
def test_encrypted_cookie_using_default_serializer
|
2012-10-30 14:41:11 -04:00
|
|
|
get :set_encrypted_cookie
|
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 'bar', cookies[:foo]
|
2014-02-05 06:15:11 -05:00
|
|
|
assert_raise TypeError do
|
2014-01-10 06:57:50 -05:00
|
|
|
cookies.signed[:foo]
|
|
|
|
end
|
|
|
|
assert_equal 'bar', cookies.encrypted[:foo]
|
|
|
|
end
|
|
|
|
|
2014-02-05 06:15:11 -05:00
|
|
|
def test_encrypted_cookie_using_marshal_serializer
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :marshal
|
2014-01-10 06:57:50 -05:00
|
|
|
get :set_encrypted_cookie
|
2014-02-05 06:15:11 -05:00
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 'bar', cookies[:foo]
|
|
|
|
assert_raises TypeError do
|
|
|
|
cookies.signed[:foo]
|
|
|
|
end
|
|
|
|
assert_equal 'bar', cookies.encrypted[:foo]
|
2014-01-10 06:57:50 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
def test_encrypted_cookie_using_json_serializer
|
2014-02-04 12:31:48 -05:00
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :json
|
2014-01-10 06:57:50 -05:00
|
|
|
get :set_encrypted_cookie
|
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 'bar', cookies[:foo]
|
2014-02-04 12:31:48 -05:00
|
|
|
assert_raises ::JSON::ParserError do
|
2012-10-30 14:41:11 -04:00
|
|
|
cookies.signed[:foo]
|
|
|
|
end
|
|
|
|
assert_equal 'bar', cookies.encrypted[:foo]
|
|
|
|
end
|
|
|
|
|
2014-08-17 15:40:24 -04:00
|
|
|
def test_wrapped_encrypted_cookie_using_json_serializer
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :json
|
|
|
|
get :set_wrapped_encrypted_cookie
|
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 'wrapped: bar', cookies[:foo]
|
|
|
|
assert_raises ::JSON::ParserError do
|
|
|
|
cookies.signed[:foo]
|
|
|
|
end
|
|
|
|
assert_equal 'wrapped: bar', cookies.encrypted[:foo]
|
|
|
|
end
|
|
|
|
|
2014-02-05 06:15:11 -05:00
|
|
|
def test_encrypted_cookie_using_custom_serializer
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = CustomSerializer
|
|
|
|
get :set_encrypted_cookie
|
2014-02-09 04:12:11 -05:00
|
|
|
assert_not_equal 'bar', cookies.encrypted[:foo]
|
2014-02-05 06:15:11 -05:00
|
|
|
assert_equal 'bar was dumped and loaded', cookies.encrypted[:foo]
|
|
|
|
end
|
|
|
|
|
2014-08-12 15:57:51 -04:00
|
|
|
def test_encrypted_cookie_using_custom_digest
|
|
|
|
@request.env["action_dispatch.cookies_digest"] = 'SHA256'
|
|
|
|
get :set_encrypted_cookie
|
|
|
|
cookies = @controller.send :cookies
|
|
|
|
assert_not_equal 'bar', cookies[:foo]
|
|
|
|
assert_equal 'bar', cookies.encrypted[:foo]
|
|
|
|
|
|
|
|
sign_secret = @request.env["action_dispatch.key_generator"].generate_key(@request.env["action_dispatch.encrypted_signed_cookie_salt"])
|
|
|
|
|
2014-08-17 14:44:31 -04:00
|
|
|
sha1_verifier = ActiveSupport::MessageVerifier.new(sign_secret, serializer: ActiveSupport::MessageEncryptor::NullSerializer, digest: 'SHA1')
|
|
|
|
sha256_verifier = ActiveSupport::MessageVerifier.new(sign_secret, serializer: ActiveSupport::MessageEncryptor::NullSerializer, digest: 'SHA256')
|
2014-08-12 15:57:51 -04:00
|
|
|
|
|
|
|
assert_raises(ActiveSupport::MessageVerifier::InvalidSignature) do
|
|
|
|
sha1_verifier.verify(cookies[:foo])
|
|
|
|
end
|
|
|
|
|
|
|
|
assert_nothing_raised do
|
|
|
|
sha256_verifier.verify(cookies[:foo])
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2014-02-08 14:28:53 -05:00
|
|
|
def test_encrypted_cookie_using_hybrid_serializer_can_migrate_marshal_dumped_value_to_json
|
2014-02-07 22:23:06 -05:00
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :hybrid
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
encrypted_cookie_salt = @request.env["action_dispatch.encrypted_cookie_salt"]
|
|
|
|
encrypted_signed_cookie_salt = @request.env["action_dispatch.encrypted_signed_cookie_salt"]
|
|
|
|
secret = key_generator.generate_key(encrypted_cookie_salt)
|
|
|
|
sign_secret = key_generator.generate_key(encrypted_signed_cookie_salt)
|
2014-02-08 14:28:53 -05:00
|
|
|
|
2014-02-09 04:12:11 -05:00
|
|
|
marshal_value = ActiveSupport::MessageEncryptor.new(secret, sign_secret, serializer: Marshal).encrypt_and_sign("bar")
|
|
|
|
@request.headers["Cookie"] = "foo=#{marshal_value}"
|
2014-02-07 22:23:06 -05:00
|
|
|
|
|
|
|
get :get_encrypted_cookie
|
|
|
|
|
|
|
|
cookies = @controller.send :cookies
|
2014-02-09 04:12:11 -05:00
|
|
|
assert_not_equal "bar", cookies[:foo]
|
|
|
|
assert_equal "bar", cookies.encrypted[:foo]
|
2014-02-08 14:28:53 -05:00
|
|
|
|
2014-02-09 04:12:11 -05:00
|
|
|
encryptor = ActiveSupport::MessageEncryptor.new(secret, sign_secret, serializer: JSON)
|
|
|
|
assert_equal "bar", encryptor.decrypt_and_verify(@response.cookies["foo"])
|
2014-02-07 22:23:06 -05:00
|
|
|
end
|
|
|
|
|
2014-02-08 13:16:43 -05:00
|
|
|
def test_encrypted_cookie_using_hybrid_serializer_can_read_from_json_dumped_value
|
2014-02-07 22:23:06 -05:00
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :hybrid
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
encrypted_cookie_salt = @request.env["action_dispatch.encrypted_cookie_salt"]
|
|
|
|
encrypted_signed_cookie_salt = @request.env["action_dispatch.encrypted_signed_cookie_salt"]
|
|
|
|
secret = key_generator.generate_key(encrypted_cookie_salt)
|
|
|
|
sign_secret = key_generator.generate_key(encrypted_signed_cookie_salt)
|
2014-02-09 04:12:11 -05:00
|
|
|
json_value = ActiveSupport::MessageEncryptor.new(secret, sign_secret, serializer: JSON).encrypt_and_sign("bar")
|
|
|
|
@request.headers["Cookie"] = "foo=#{json_value}"
|
2014-02-07 22:23:06 -05:00
|
|
|
|
|
|
|
get :get_encrypted_cookie
|
|
|
|
|
|
|
|
cookies = @controller.send :cookies
|
2014-02-09 04:12:11 -05:00
|
|
|
assert_not_equal "bar", cookies[:foo]
|
|
|
|
assert_equal "bar", cookies.encrypted[:foo]
|
|
|
|
|
|
|
|
assert_nil @response.cookies["foo"]
|
2014-02-07 22:23:06 -05:00
|
|
|
end
|
|
|
|
|
2014-12-02 19:19:10 -05:00
|
|
|
def test_accessing_nonexistent_encrypted_cookie_should_not_raise_invalid_message
|
2013-02-19 07:35:03 -05:00
|
|
|
get :set_encrypted_cookie
|
|
|
|
assert_nil @controller.send(:cookies).encrypted[:non_existant_attribute]
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_setting_invalid_encrypted_cookie_should_return_nil_when_accessing_it
|
|
|
|
get :set_invalid_encrypted_cookie
|
|
|
|
assert_nil @controller.send(:cookies).encrypted[:invalid_cookie]
|
2010-01-17 22:30:38 -05:00
|
|
|
end
|
|
|
|
|
2009-12-20 17:33:13 -05:00
|
|
|
def test_permanent_signed_cookie
|
|
|
|
get :set_permanent_signed_cookie
|
2010-09-22 15:03:39 -04:00
|
|
|
assert_match(%r(#{20.years.from_now.utc.year}), @response.headers["Set-Cookie"])
|
2009-12-20 17:33:13 -05:00
|
|
|
assert_equal 100, @controller.send(:cookies).signed[:remember_me]
|
|
|
|
end
|
|
|
|
|
2010-03-17 20:15:52 -04:00
|
|
|
def test_delete_and_set_cookie
|
2012-04-30 08:32:53 -04:00
|
|
|
request.cookies[:user_name] = 'Joe'
|
2010-03-17 20:15:52 -04:00
|
|
|
get :delete_and_set_cookie
|
2013-01-10 22:34:52 -05:00
|
|
|
assert_cookie_header "user_name=david; path=/; expires=Mon, 10 Oct 2005 05:00:00 -0000"
|
2010-03-17 20:15:52 -04:00
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
|
|
|
end
|
2010-01-16 18:21:46 -05:00
|
|
|
|
2010-05-17 19:43:06 -04:00
|
|
|
def test_raise_data_overflow
|
|
|
|
assert_raise(ActionDispatch::Cookies::CookieOverflow) do
|
|
|
|
get :raise_data_overflow
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_tampered_cookies
|
|
|
|
assert_nothing_raised do
|
|
|
|
get :tampered_cookies
|
|
|
|
assert_response :success
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2015-09-01 04:20:32 -04:00
|
|
|
def test_cookie_jar_mutated_by_request_persists_on_future_requests
|
|
|
|
get :authenticate
|
|
|
|
cookie_jar = @request.cookie_jar
|
|
|
|
cookie_jar.signed[:user_id] = 123
|
|
|
|
assert_equal ["user_name", "user_id"], @request.cookie_jar.instance_variable_get(:@cookies).keys
|
|
|
|
get :get_signed_cookie
|
|
|
|
assert_equal ["user_name", "user_id"], @request.cookie_jar.instance_variable_get(:@cookies).keys
|
|
|
|
end
|
|
|
|
|
2010-05-17 19:43:06 -04:00
|
|
|
def test_raises_argument_error_if_missing_secret
|
|
|
|
assert_raise(ArgumentError, nil.inspect) {
|
2013-04-02 19:41:57 -04:00
|
|
|
@request.env["action_dispatch.key_generator"] = ActiveSupport::LegacyKeyGenerator.new(nil)
|
2010-05-17 19:43:06 -04:00
|
|
|
get :set_signed_cookie
|
|
|
|
}
|
|
|
|
|
|
|
|
assert_raise(ArgumentError, ''.inspect) {
|
2013-04-02 19:41:57 -04:00
|
|
|
@request.env["action_dispatch.key_generator"] = ActiveSupport::LegacyKeyGenerator.new("")
|
2010-05-17 19:43:06 -04:00
|
|
|
get :set_signed_cookie
|
|
|
|
}
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_raises_argument_error_if_secret_is_probably_insecure
|
|
|
|
assert_raise(ArgumentError, "password".inspect) {
|
2013-04-02 19:41:57 -04:00
|
|
|
@request.env["action_dispatch.key_generator"] = ActiveSupport::LegacyKeyGenerator.new("password")
|
2010-05-17 19:43:06 -04:00
|
|
|
get :set_signed_cookie
|
|
|
|
}
|
|
|
|
|
|
|
|
assert_raise(ArgumentError, "secret".inspect) {
|
2013-04-02 19:41:57 -04:00
|
|
|
@request.env["action_dispatch.key_generator"] = ActiveSupport::LegacyKeyGenerator.new("secret")
|
2010-05-17 19:43:06 -04:00
|
|
|
get :set_signed_cookie
|
|
|
|
}
|
|
|
|
|
|
|
|
assert_raise(ArgumentError, "12345678901234567890123456789".inspect) {
|
2013-04-02 19:41:57 -04:00
|
|
|
@request.env["action_dispatch.key_generator"] = ActiveSupport::LegacyKeyGenerator.new("12345678901234567890123456789")
|
2010-05-17 19:43:06 -04:00
|
|
|
get :set_signed_cookie
|
|
|
|
}
|
|
|
|
end
|
|
|
|
|
2013-03-24 19:20:24 -04:00
|
|
|
def test_signed_uses_signed_cookie_jar_if_only_secret_token_is_set
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = nil
|
|
|
|
get :set_signed_cookie
|
|
|
|
assert_kind_of ActionDispatch::Cookies::SignedCookieJar, cookies.signed
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_signed_uses_signed_cookie_jar_if_only_secret_key_base_is_set
|
|
|
|
@request.env["action_dispatch.secret_token"] = nil
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
get :set_signed_cookie
|
|
|
|
assert_kind_of ActionDispatch::Cookies::SignedCookieJar, cookies.signed
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_signed_uses_upgrade_legacy_signed_cookie_jar_if_both_secret_token_and_secret_key_base_are_set
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
get :set_signed_cookie
|
|
|
|
assert_kind_of ActionDispatch::Cookies::UpgradeLegacySignedCookieJar, cookies.signed
|
|
|
|
end
|
|
|
|
|
2013-03-28 15:35:48 -04:00
|
|
|
def test_signed_or_encrypted_uses_signed_cookie_jar_if_only_secret_token_is_set
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = nil
|
|
|
|
get :get_encrypted_cookie
|
|
|
|
assert_kind_of ActionDispatch::Cookies::SignedCookieJar, cookies.signed_or_encrypted
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_signed_or_encrypted_uses_encrypted_cookie_jar_if_only_secret_key_base_is_set
|
|
|
|
@request.env["action_dispatch.secret_token"] = nil
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
get :get_encrypted_cookie
|
|
|
|
assert_kind_of ActionDispatch::Cookies::EncryptedCookieJar, cookies.signed_or_encrypted
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_signed_or_encrypted_uses_upgrade_legacy_encrypted_cookie_jar_if_both_secret_token_and_secret_key_base_are_set
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
get :get_encrypted_cookie
|
|
|
|
assert_kind_of ActionDispatch::Cookies::UpgradeLegacyEncryptedCookieJar, cookies.signed_or_encrypted
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_encrypted_uses_encrypted_cookie_jar_if_only_secret_key_base_is_set
|
|
|
|
@request.env["action_dispatch.secret_token"] = nil
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
get :get_encrypted_cookie
|
|
|
|
assert_kind_of ActionDispatch::Cookies::EncryptedCookieJar, cookies.encrypted
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_encrypted_uses_upgrade_legacy_encrypted_cookie_jar_if_both_secret_token_and_secret_key_base_are_set
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
get :get_encrypted_cookie
|
|
|
|
assert_kind_of ActionDispatch::Cookies::UpgradeLegacyEncryptedCookieJar, cookies.encrypted
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_legacy_signed_cookie_is_read_and_transparently_upgraded_by_signed_cookie_jar_if_both_secret_token_and_secret_key_base_are_set
|
2013-03-24 19:20:24 -04:00
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
|
|
|
|
legacy_value = ActiveSupport::MessageVerifier.new("b3c631c314c0bbca50c1b2843150fe33").generate(45)
|
|
|
|
|
|
|
|
@request.headers["Cookie"] = "user_id=#{legacy_value}"
|
|
|
|
get :get_signed_cookie
|
|
|
|
|
|
|
|
assert_equal 45, @controller.send(:cookies).signed[:user_id]
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
secret = key_generator.generate_key(@request.env["action_dispatch.signed_cookie_salt"])
|
|
|
|
verifier = ActiveSupport::MessageVerifier.new(secret)
|
|
|
|
assert_equal 45, verifier.verify(@response.cookies["user_id"])
|
|
|
|
end
|
|
|
|
|
2013-03-28 15:35:48 -04:00
|
|
|
def test_legacy_signed_cookie_is_read_and_transparently_encrypted_by_encrypted_cookie_jar_if_both_secret_token_and_secret_key_base_are_set
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
@request.env["action_dispatch.encrypted_cookie_salt"] = "4433796b79d99a7735553e316522acee"
|
|
|
|
@request.env["action_dispatch.encrypted_signed_cookie_salt"] = "00646eb40062e1b1deff205a27cd30f9"
|
|
|
|
|
|
|
|
legacy_value = ActiveSupport::MessageVerifier.new("b3c631c314c0bbca50c1b2843150fe33").generate('bar')
|
|
|
|
|
|
|
|
@request.headers["Cookie"] = "foo=#{legacy_value}"
|
|
|
|
get :get_encrypted_cookie
|
|
|
|
|
|
|
|
assert_equal 'bar', @controller.send(:cookies).encrypted[:foo]
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
secret = key_generator.generate_key(@request.env["action_dispatch.encrypted_cookie_salt"])
|
|
|
|
sign_secret = key_generator.generate_key(@request.env["action_dispatch.encrypted_signed_cookie_salt"])
|
|
|
|
encryptor = ActiveSupport::MessageEncryptor.new(secret, sign_secret)
|
|
|
|
assert_equal 'bar', encryptor.decrypt_and_verify(@response.cookies["foo"])
|
|
|
|
end
|
|
|
|
|
2014-04-23 12:07:50 -04:00
|
|
|
def test_legacy_json_signed_cookie_is_read_and_transparently_upgraded_by_signed_json_cookie_jar_if_both_secret_token_and_secret_key_base_are_set
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :json
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
|
|
|
|
legacy_value = ActiveSupport::MessageVerifier.new("b3c631c314c0bbca50c1b2843150fe33", serializer: JSON).generate(45)
|
|
|
|
|
|
|
|
@request.headers["Cookie"] = "user_id=#{legacy_value}"
|
|
|
|
get :get_signed_cookie
|
|
|
|
|
|
|
|
assert_equal 45, @controller.send(:cookies).signed[:user_id]
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
secret = key_generator.generate_key(@request.env["action_dispatch.signed_cookie_salt"])
|
|
|
|
verifier = ActiveSupport::MessageVerifier.new(secret, serializer: JSON)
|
|
|
|
assert_equal 45, verifier.verify(@response.cookies["user_id"])
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_legacy_json_signed_cookie_is_read_and_transparently_encrypted_by_encrypted_json_cookie_jar_if_both_secret_token_and_secret_key_base_are_set
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :json
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
@request.env["action_dispatch.encrypted_cookie_salt"] = "4433796b79d99a7735553e316522acee"
|
|
|
|
@request.env["action_dispatch.encrypted_signed_cookie_salt"] = "00646eb40062e1b1deff205a27cd30f9"
|
|
|
|
|
|
|
|
legacy_value = ActiveSupport::MessageVerifier.new("b3c631c314c0bbca50c1b2843150fe33", serializer: JSON).generate('bar')
|
|
|
|
|
|
|
|
@request.headers["Cookie"] = "foo=#{legacy_value}"
|
|
|
|
get :get_encrypted_cookie
|
|
|
|
|
|
|
|
assert_equal 'bar', @controller.send(:cookies).encrypted[:foo]
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
secret = key_generator.generate_key(@request.env["action_dispatch.encrypted_cookie_salt"])
|
|
|
|
sign_secret = key_generator.generate_key(@request.env["action_dispatch.encrypted_signed_cookie_salt"])
|
|
|
|
encryptor = ActiveSupport::MessageEncryptor.new(secret, sign_secret, serializer: JSON)
|
|
|
|
assert_equal 'bar', encryptor.decrypt_and_verify(@response.cookies["foo"])
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_legacy_json_signed_cookie_is_read_and_transparently_upgraded_by_signed_json_hybrid_jar_if_both_secret_token_and_secret_key_base_are_set
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :hybrid
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
|
|
|
|
legacy_value = ActiveSupport::MessageVerifier.new("b3c631c314c0bbca50c1b2843150fe33", serializer: JSON).generate(45)
|
|
|
|
|
|
|
|
@request.headers["Cookie"] = "user_id=#{legacy_value}"
|
|
|
|
get :get_signed_cookie
|
|
|
|
|
|
|
|
assert_equal 45, @controller.send(:cookies).signed[:user_id]
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
secret = key_generator.generate_key(@request.env["action_dispatch.signed_cookie_salt"])
|
|
|
|
verifier = ActiveSupport::MessageVerifier.new(secret, serializer: JSON)
|
|
|
|
assert_equal 45, verifier.verify(@response.cookies["user_id"])
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_legacy_json_signed_cookie_is_read_and_transparently_encrypted_by_encrypted_hybrid_cookie_jar_if_both_secret_token_and_secret_key_base_are_set
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :hybrid
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
@request.env["action_dispatch.encrypted_cookie_salt"] = "4433796b79d99a7735553e316522acee"
|
|
|
|
@request.env["action_dispatch.encrypted_signed_cookie_salt"] = "00646eb40062e1b1deff205a27cd30f9"
|
|
|
|
|
|
|
|
legacy_value = ActiveSupport::MessageVerifier.new("b3c631c314c0bbca50c1b2843150fe33", serializer: JSON).generate('bar')
|
|
|
|
|
|
|
|
@request.headers["Cookie"] = "foo=#{legacy_value}"
|
|
|
|
get :get_encrypted_cookie
|
|
|
|
|
|
|
|
assert_equal 'bar', @controller.send(:cookies).encrypted[:foo]
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
secret = key_generator.generate_key(@request.env["action_dispatch.encrypted_cookie_salt"])
|
|
|
|
sign_secret = key_generator.generate_key(@request.env["action_dispatch.encrypted_signed_cookie_salt"])
|
|
|
|
encryptor = ActiveSupport::MessageEncryptor.new(secret, sign_secret, serializer: JSON)
|
|
|
|
assert_equal 'bar', encryptor.decrypt_and_verify(@response.cookies["foo"])
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_legacy_marshal_signed_cookie_is_read_and_transparently_upgraded_by_signed_json_hybrid_jar_if_both_secret_token_and_secret_key_base_are_set
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :hybrid
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
|
|
|
|
legacy_value = ActiveSupport::MessageVerifier.new("b3c631c314c0bbca50c1b2843150fe33").generate(45)
|
|
|
|
|
|
|
|
@request.headers["Cookie"] = "user_id=#{legacy_value}"
|
|
|
|
get :get_signed_cookie
|
|
|
|
|
|
|
|
assert_equal 45, @controller.send(:cookies).signed[:user_id]
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
secret = key_generator.generate_key(@request.env["action_dispatch.signed_cookie_salt"])
|
|
|
|
verifier = ActiveSupport::MessageVerifier.new(secret, serializer: JSON)
|
|
|
|
assert_equal 45, verifier.verify(@response.cookies["user_id"])
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_legacy_marshal_signed_cookie_is_read_and_transparently_encrypted_by_encrypted_hybrid_cookie_jar_if_both_secret_token_and_secret_key_base_are_set
|
|
|
|
@request.env["action_dispatch.cookies_serializer"] = :hybrid
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
@request.env["action_dispatch.encrypted_cookie_salt"] = "4433796b79d99a7735553e316522acee"
|
|
|
|
@request.env["action_dispatch.encrypted_signed_cookie_salt"] = "00646eb40062e1b1deff205a27cd30f9"
|
|
|
|
|
|
|
|
legacy_value = ActiveSupport::MessageVerifier.new("b3c631c314c0bbca50c1b2843150fe33").generate('bar')
|
|
|
|
|
|
|
|
@request.headers["Cookie"] = "foo=#{legacy_value}"
|
|
|
|
get :get_encrypted_cookie
|
|
|
|
|
|
|
|
assert_equal 'bar', @controller.send(:cookies).encrypted[:foo]
|
|
|
|
|
|
|
|
key_generator = @request.env["action_dispatch.key_generator"]
|
|
|
|
secret = key_generator.generate_key(@request.env["action_dispatch.encrypted_cookie_salt"])
|
|
|
|
sign_secret = key_generator.generate_key(@request.env["action_dispatch.encrypted_signed_cookie_salt"])
|
|
|
|
encryptor = ActiveSupport::MessageEncryptor.new(secret, sign_secret, serializer: JSON)
|
|
|
|
assert_equal 'bar', encryptor.decrypt_and_verify(@response.cookies["foo"])
|
|
|
|
end
|
|
|
|
|
2013-03-28 15:35:48 -04:00
|
|
|
def test_legacy_signed_cookie_is_treated_as_nil_by_signed_cookie_jar_if_tampered
|
2013-03-24 19:20:24 -04:00
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
|
|
|
|
@request.headers["Cookie"] = "user_id=45"
|
|
|
|
get :get_signed_cookie
|
|
|
|
|
|
|
|
assert_equal nil, @controller.send(:cookies).signed[:user_id]
|
|
|
|
assert_equal nil, @response.cookies["user_id"]
|
|
|
|
end
|
|
|
|
|
2013-03-28 15:35:48 -04:00
|
|
|
def test_legacy_signed_cookie_is_treated_as_nil_by_encrypted_cookie_jar_if_tampered
|
|
|
|
@request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
|
|
|
|
@request.env["action_dispatch.secret_key_base"] = "c3b95688f35581fad38df788add315ff"
|
|
|
|
|
|
|
|
@request.headers["Cookie"] = "foo=baz"
|
|
|
|
get :get_encrypted_cookie
|
|
|
|
|
|
|
|
assert_equal nil, @controller.send(:cookies).encrypted[:foo]
|
|
|
|
assert_equal nil, @response.cookies["foo"]
|
|
|
|
end
|
|
|
|
|
2010-06-11 06:00:35 -04:00
|
|
|
def test_cookie_with_all_domain_option
|
|
|
|
get :set_cookie_with_domain
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; domain=.nextangle.com; path=/"
|
|
|
|
end
|
|
|
|
|
2010-08-14 15:35:01 -04:00
|
|
|
def test_cookie_with_all_domain_option_using_a_non_standard_tld
|
|
|
|
@request.host = "two.subdomains.nextangle.local"
|
|
|
|
get :set_cookie_with_domain
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; domain=.nextangle.local; path=/"
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_cookie_with_all_domain_option_using_australian_style_tld
|
|
|
|
@request.host = "nextangle.com.au"
|
|
|
|
get :set_cookie_with_domain
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; domain=.nextangle.com.au; path=/"
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_cookie_with_all_domain_option_using_uk_style_tld
|
|
|
|
@request.host = "nextangle.co.uk"
|
|
|
|
get :set_cookie_with_domain
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; domain=.nextangle.co.uk; path=/"
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_cookie_with_all_domain_option_using_host_with_port
|
|
|
|
@request.host = "nextangle.local:3000"
|
|
|
|
get :set_cookie_with_domain
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; domain=.nextangle.local; path=/"
|
|
|
|
end
|
|
|
|
|
2010-12-09 10:38:52 -05:00
|
|
|
def test_cookie_with_all_domain_option_using_localhost
|
|
|
|
@request.host = "localhost"
|
|
|
|
get :set_cookie_with_domain
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; path=/"
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_cookie_with_all_domain_option_using_ipv4_address
|
|
|
|
@request.host = "192.168.1.1"
|
|
|
|
get :set_cookie_with_domain
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; path=/"
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_cookie_with_all_domain_option_using_ipv6_address
|
|
|
|
@request.host = "2001:0db8:85a3:0000:0000:8a2e:0370:7334"
|
|
|
|
get :set_cookie_with_domain
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; path=/"
|
|
|
|
end
|
|
|
|
|
2010-06-11 06:00:35 -04:00
|
|
|
def test_deleting_cookie_with_all_domain_option
|
2012-04-30 08:32:53 -04:00
|
|
|
request.cookies[:user_name] = 'Joe'
|
2010-06-11 06:00:35 -04:00
|
|
|
get :delete_cookie_with_domain
|
|
|
|
assert_response :success
|
2013-01-10 22:34:52 -05:00
|
|
|
assert_cookie_header "user_name=; domain=.nextangle.com; path=/; max-age=0; expires=Thu, 01 Jan 1970 00:00:00 -0000"
|
2010-06-11 06:00:35 -04:00
|
|
|
end
|
|
|
|
|
2011-01-21 06:59:49 -05:00
|
|
|
def test_cookie_with_all_domain_option_and_tld_length
|
|
|
|
get :set_cookie_with_domain_and_tld
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; domain=.nextangle.com; path=/"
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_cookie_with_all_domain_option_using_a_non_standard_tld_and_tld_length
|
|
|
|
@request.host = "two.subdomains.nextangle.local"
|
|
|
|
get :set_cookie_with_domain_and_tld
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; domain=.nextangle.local; path=/"
|
|
|
|
end
|
|
|
|
|
2013-04-30 00:26:29 -04:00
|
|
|
def test_cookie_with_all_domain_option_using_a_non_standard_2_letter_tld
|
|
|
|
@request.host = "admin.lvh.me"
|
|
|
|
get :set_cookie_with_domain_and_tld
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; domain=.lvh.me; path=/"
|
|
|
|
end
|
|
|
|
|
2011-01-21 06:59:49 -05:00
|
|
|
def test_cookie_with_all_domain_option_using_host_with_port_and_tld_length
|
|
|
|
@request.host = "nextangle.local:3000"
|
|
|
|
get :set_cookie_with_domain_and_tld
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; domain=.nextangle.local; path=/"
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_deleting_cookie_with_all_domain_option_and_tld_length
|
2012-04-30 08:32:53 -04:00
|
|
|
request.cookies[:user_name] = 'Joe'
|
2011-01-21 06:59:49 -05:00
|
|
|
get :delete_cookie_with_domain_and_tld
|
|
|
|
assert_response :success
|
2013-01-10 22:34:52 -05:00
|
|
|
assert_cookie_header "user_name=; domain=.nextangle.com; path=/; max-age=0; expires=Thu, 01 Jan 1970 00:00:00 -0000"
|
2011-01-21 06:59:49 -05:00
|
|
|
end
|
|
|
|
|
2011-01-21 06:58:33 -05:00
|
|
|
def test_cookie_with_several_preset_domains_using_one_of_these_domains
|
|
|
|
@request.host = "example1.com"
|
|
|
|
get :set_cookie_with_domains
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; domain=example1.com; path=/"
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_cookie_with_several_preset_domains_using_other_domain
|
|
|
|
@request.host = "other-domain.com"
|
|
|
|
get :set_cookie_with_domains
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; path=/"
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_cookie_with_several_preset_domains_using_shared_domain
|
|
|
|
@request.host = "example3.com"
|
|
|
|
get :set_cookie_with_domains
|
|
|
|
assert_response :success
|
|
|
|
assert_cookie_header "user_name=rizwanreza; domain=.example3.com; path=/"
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_deletings_cookie_with_several_preset_domains_using_one_of_these_domains
|
|
|
|
@request.host = "example2.com"
|
2012-04-30 08:32:53 -04:00
|
|
|
request.cookies[:user_name] = 'Joe'
|
2011-01-21 06:58:33 -05:00
|
|
|
get :delete_cookie_with_domains
|
|
|
|
assert_response :success
|
2013-01-10 22:34:52 -05:00
|
|
|
assert_cookie_header "user_name=; domain=example2.com; path=/; max-age=0; expires=Thu, 01 Jan 1970 00:00:00 -0000"
|
2011-01-21 06:58:33 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
def test_deletings_cookie_with_several_preset_domains_using_other_domain
|
|
|
|
@request.host = "other-domain.com"
|
2012-04-30 08:32:53 -04:00
|
|
|
request.cookies[:user_name] = 'Joe'
|
2011-01-21 06:58:33 -05:00
|
|
|
get :delete_cookie_with_domains
|
|
|
|
assert_response :success
|
2013-01-10 22:34:52 -05:00
|
|
|
assert_cookie_header "user_name=; path=/; max-age=0; expires=Thu, 01 Jan 1970 00:00:00 -0000"
|
2011-01-21 06:58:33 -05:00
|
|
|
end
|
|
|
|
|
2010-10-13 14:58:25 -04:00
|
|
|
def test_cookies_hash_is_indifferent_access
|
2012-04-30 08:32:53 -04:00
|
|
|
get :symbol_key
|
|
|
|
assert_equal "david", cookies[:user_name]
|
|
|
|
assert_equal "david", cookies['user_name']
|
|
|
|
get :string_key
|
|
|
|
assert_equal "dhh", cookies[:user_name]
|
|
|
|
assert_equal "dhh", cookies['user_name']
|
2010-10-13 14:58:25 -04:00
|
|
|
end
|
|
|
|
|
2011-03-06 07:49:44 -05:00
|
|
|
def test_setting_request_cookies_is_indifferent_access
|
2011-03-29 19:46:27 -04:00
|
|
|
cookies.clear
|
|
|
|
cookies[:user_name] = "andrew"
|
2011-03-06 07:49:44 -05:00
|
|
|
get :string_key_mock
|
2011-03-29 19:46:27 -04:00
|
|
|
assert_equal "david", cookies['user_name']
|
2011-03-06 07:49:44 -05:00
|
|
|
|
2011-03-29 19:46:27 -04:00
|
|
|
cookies.clear
|
|
|
|
cookies['user_name'] = "andrew"
|
2011-03-06 07:49:44 -05:00
|
|
|
get :symbol_key_mock
|
2011-03-29 19:46:27 -04:00
|
|
|
assert_equal "david", cookies[:user_name]
|
2011-03-06 07:49:44 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
def test_cookies_retained_across_requests
|
|
|
|
get :symbol_key
|
2011-03-29 19:46:27 -04:00
|
|
|
assert_cookie_header "user_name=david; path=/"
|
2011-03-06 07:49:44 -05:00
|
|
|
assert_equal "david", cookies[:user_name]
|
|
|
|
|
|
|
|
get :noop
|
2015-10-01 21:47:13 -04:00
|
|
|
assert !@response.headers.include?("Set-Cookie")
|
2011-03-06 07:49:44 -05:00
|
|
|
assert_equal "david", cookies[:user_name]
|
|
|
|
|
|
|
|
get :noop
|
2015-10-01 21:47:13 -04:00
|
|
|
assert !@response.headers.include?("Set-Cookie")
|
2011-03-06 07:49:44 -05:00
|
|
|
assert_equal "david", cookies[:user_name]
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_cookies_can_be_cleared
|
|
|
|
get :symbol_key
|
|
|
|
assert_equal "david", cookies[:user_name]
|
|
|
|
|
2011-03-29 19:46:27 -04:00
|
|
|
cookies.clear
|
2011-03-06 07:49:44 -05:00
|
|
|
get :noop
|
|
|
|
assert_nil cookies[:user_name]
|
|
|
|
|
|
|
|
get :symbol_key
|
|
|
|
assert_equal "david", cookies[:user_name]
|
|
|
|
end
|
|
|
|
|
2011-03-29 19:46:27 -04:00
|
|
|
def test_can_set_http_cookie_header
|
2011-06-05 07:34:27 -04:00
|
|
|
@request.env['HTTP_COOKIE'] = 'user_name=david'
|
|
|
|
get :noop
|
|
|
|
assert_equal 'david', cookies['user_name']
|
|
|
|
assert_equal 'david', cookies[:user_name]
|
|
|
|
|
|
|
|
get :noop
|
|
|
|
assert_equal 'david', cookies['user_name']
|
|
|
|
assert_equal 'david', cookies[:user_name]
|
|
|
|
|
|
|
|
@request.env['HTTP_COOKIE'] = 'user_name=andrew'
|
|
|
|
get :noop
|
|
|
|
assert_equal 'andrew', cookies['user_name']
|
|
|
|
assert_equal 'andrew', cookies[:user_name]
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_can_set_request_cookies
|
|
|
|
@request.cookies['user_name'] = 'david'
|
|
|
|
get :noop
|
|
|
|
assert_equal 'david', cookies['user_name']
|
|
|
|
assert_equal 'david', cookies[:user_name]
|
|
|
|
|
|
|
|
get :noop
|
|
|
|
assert_equal 'david', cookies['user_name']
|
|
|
|
assert_equal 'david', cookies[:user_name]
|
|
|
|
|
|
|
|
@request.cookies[:user_name] = 'andrew'
|
|
|
|
get :noop
|
|
|
|
assert_equal 'andrew', cookies['user_name']
|
|
|
|
assert_equal 'andrew', cookies[:user_name]
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_cookies_precedence_over_http_cookie
|
|
|
|
@request.env['HTTP_COOKIE'] = 'user_name=andrew'
|
|
|
|
get :authenticate
|
|
|
|
assert_equal 'david', cookies['user_name']
|
|
|
|
assert_equal 'david', cookies[:user_name]
|
|
|
|
|
|
|
|
get :noop
|
|
|
|
assert_equal 'david', cookies['user_name']
|
|
|
|
assert_equal 'david', cookies[:user_name]
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_cookies_precedence_over_request_cookies
|
|
|
|
@request.cookies['user_name'] = 'andrew'
|
|
|
|
get :authenticate
|
|
|
|
assert_equal 'david', cookies['user_name']
|
|
|
|
assert_equal 'david', cookies[:user_name]
|
|
|
|
|
2011-03-06 07:49:44 -05:00
|
|
|
get :noop
|
2011-03-29 19:46:27 -04:00
|
|
|
assert_equal 'david', cookies['user_name']
|
|
|
|
assert_equal 'david', cookies[:user_name]
|
2011-03-06 07:49:44 -05:00
|
|
|
end
|
|
|
|
|
2009-05-22 19:57:45 -04:00
|
|
|
private
|
|
|
|
def assert_cookie_header(expected)
|
|
|
|
header = @response.headers["Set-Cookie"]
|
|
|
|
if header.respond_to?(:to_str)
|
2010-03-03 19:06:15 -05:00
|
|
|
assert_equal expected.split("\n").sort, header.split("\n").sort
|
2009-05-22 19:57:45 -04:00
|
|
|
else
|
|
|
|
assert_equal expected.split("\n"), header
|
|
|
|
end
|
|
|
|
end
|
2010-10-22 10:34:45 -04:00
|
|
|
|
|
|
|
def assert_not_cookie_header(expected)
|
|
|
|
header = @response.headers["Set-Cookie"]
|
|
|
|
if header.respond_to?(:to_str)
|
|
|
|
assert_not_equal expected.split("\n").sort, header.split("\n").sort
|
|
|
|
else
|
|
|
|
assert_not_equal expected.split("\n"), header
|
|
|
|
end
|
|
|
|
end
|
2012-04-30 08:32:53 -04:00
|
|
|
end
|