mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-10-08 07:31:29 +02:00
feat(config): convert cookie property (Not)HTTPOnly boolean to enum
Signed-off-by: Jan Larwig <jan@larwig.com>
This commit is contained in:
+122
-122
@@ -74,14 +74,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with valid configuration",
|
||||
cookie: options.Cookie{
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: domains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "",
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: domains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "",
|
||||
},
|
||||
refresh: 15 * time.Minute,
|
||||
errStrings: []string{},
|
||||
@@ -94,12 +94,12 @@ func TestValidateCookie(t *testing.T) {
|
||||
Value: nil,
|
||||
FromFile: "",
|
||||
},
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "",
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "",
|
||||
},
|
||||
refresh: 15 * time.Minute,
|
||||
errStrings: []string{
|
||||
@@ -109,14 +109,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with an invalid cookie secret",
|
||||
cookie: options.Cookie{
|
||||
Name: validName,
|
||||
Secret: invalidSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "",
|
||||
Name: validName,
|
||||
Secret: invalidSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "",
|
||||
},
|
||||
refresh: 15 * time.Minute,
|
||||
errStrings: []string{
|
||||
@@ -126,14 +126,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with a valid Base64 secret",
|
||||
cookie: options.Cookie{
|
||||
Name: validName,
|
||||
Secret: validBase64Secret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "",
|
||||
Name: validName,
|
||||
Secret: validBase64Secret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "",
|
||||
},
|
||||
refresh: 15 * time.Minute,
|
||||
errStrings: []string{},
|
||||
@@ -141,14 +141,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with an invalid Base64 secret",
|
||||
cookie: options.Cookie{
|
||||
Name: validName,
|
||||
Secret: invalidBase64Secret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "",
|
||||
Name: validName,
|
||||
Secret: invalidBase64Secret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "",
|
||||
},
|
||||
refresh: 15 * time.Minute,
|
||||
errStrings: []string{
|
||||
@@ -158,14 +158,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with an invalid name",
|
||||
cookie: options.Cookie{
|
||||
Name: invalidName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "",
|
||||
Name: invalidName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "",
|
||||
},
|
||||
refresh: 15 * time.Minute,
|
||||
errStrings: []string{
|
||||
@@ -175,14 +175,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with a name that is too long",
|
||||
cookie: options.Cookie{
|
||||
Name: longName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "",
|
||||
Name: longName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "",
|
||||
},
|
||||
refresh: 15 * time.Minute,
|
||||
errStrings: []string{
|
||||
@@ -192,14 +192,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with refresh longer than expire",
|
||||
cookie: options.Cookie{
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: 15 * time.Minute,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "",
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: 15 * time.Minute,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "",
|
||||
},
|
||||
refresh: time.Hour,
|
||||
errStrings: []string{
|
||||
@@ -209,14 +209,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with samesite \"none\"",
|
||||
cookie: options.Cookie{
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "none",
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "none",
|
||||
},
|
||||
refresh: 15 * time.Minute,
|
||||
errStrings: []string{},
|
||||
@@ -224,14 +224,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with samesite \"lax\"",
|
||||
cookie: options.Cookie{
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "none",
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "none",
|
||||
},
|
||||
refresh: 15 * time.Minute,
|
||||
errStrings: []string{},
|
||||
@@ -239,14 +239,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with samesite \"strict\"",
|
||||
cookie: options.Cookie{
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "none",
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "none",
|
||||
},
|
||||
refresh: 15 * time.Minute,
|
||||
errStrings: []string{},
|
||||
@@ -254,14 +254,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with samesite \"invalid\"",
|
||||
cookie: options.Cookie{
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "invalid",
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: emptyDomains,
|
||||
Path: "",
|
||||
Expire: time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "invalid",
|
||||
},
|
||||
refresh: 15 * time.Minute,
|
||||
errStrings: []string{
|
||||
@@ -271,14 +271,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with a combination of configuration errors",
|
||||
cookie: options.Cookie{
|
||||
Name: invalidName,
|
||||
Secret: invalidSecret,
|
||||
Domains: domains,
|
||||
Path: "",
|
||||
Expire: 15 * time.Minute,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "invalid",
|
||||
Name: invalidName,
|
||||
Secret: invalidSecret,
|
||||
Domains: domains,
|
||||
Path: "",
|
||||
Expire: 15 * time.Minute,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "invalid",
|
||||
},
|
||||
refresh: time.Hour,
|
||||
errStrings: []string{
|
||||
@@ -291,14 +291,14 @@ func TestValidateCookie(t *testing.T) {
|
||||
{
|
||||
name: "with session cookie configuration",
|
||||
cookie: options.Cookie{
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: domains,
|
||||
Path: "",
|
||||
Expire: 0,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(true),
|
||||
SameSite: "",
|
||||
Name: validName,
|
||||
Secret: validSecret,
|
||||
Domains: domains,
|
||||
Path: "",
|
||||
Expire: 0,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessAllowed,
|
||||
SameSite: "",
|
||||
},
|
||||
refresh: 15 * time.Minute,
|
||||
errStrings: []string{},
|
||||
@@ -310,12 +310,12 @@ func TestValidateCookie(t *testing.T) {
|
||||
Secret: options.SecretSource{
|
||||
FromFile: tmpfile.Name(),
|
||||
},
|
||||
Domains: domains,
|
||||
Path: "",
|
||||
Expire: 24 * time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(false),
|
||||
SameSite: "",
|
||||
Domains: domains,
|
||||
Path: "",
|
||||
Expire: 24 * time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessDenied,
|
||||
SameSite: "",
|
||||
},
|
||||
refresh: 0,
|
||||
errStrings: []string{},
|
||||
@@ -327,12 +327,12 @@ func TestValidateCookie(t *testing.T) {
|
||||
Secret: options.SecretSource{
|
||||
FromFile: "/nonexistent/file.txt",
|
||||
},
|
||||
Domains: domains,
|
||||
Path: "",
|
||||
Expire: 24 * time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
NotHttpOnly: ptr.To(false),
|
||||
SameSite: "",
|
||||
Domains: domains,
|
||||
Path: "",
|
||||
Expire: 24 * time.Hour,
|
||||
Insecure: ptr.To(false),
|
||||
ScriptAccess: options.ScriptAccessDenied,
|
||||
SameSite: "",
|
||||
},
|
||||
refresh: 0,
|
||||
errStrings: []string{"could not read cookie secret file: /nonexistent/file.txt"},
|
||||
|
||||
Reference in New Issue
Block a user