Test the Secure flag of the session cookie - #26
Merged
Merged
Conversation
Move the cookie parameters into sessionCookieParams() and unit test them for HTTPS on/off/empty/unset/1. X-Forwarded-Proto is deliberately not trusted; an integration test checks that the header does not set the Secure flag. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018sYJSnbvafWtzadV4wcKZx
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds automated tests for the
Secureflag of the session cookie (issue #17), using the cheaper option from the issue instead of TLS in the web server tests.auth.phpintosessionCookieParams()/isHttpsRequest()inauth_functions.php. Behaviour is unchanged.HTTPS=on,1,off, empty and unset. They also check thatHttpOnly,SameSite=Laxand the path are always set.X-Forwarded-Protostays untrusted, because any client can send it. Behind a TLS-terminating proxy the cookie therefore never getsSecure. This is documented in the function comment, and no trusted-proxies setting is added.X-Forwarded-Proto/X-Forwarded-Sslheaders over plain HTTP and checks that noSecureflag is set.HttpClient::get()gained optional request headers for this.Not covered
The curl check against Apache (
mod_ssl) and nginx with a self-signed certificate intests/Server/run.shis not done. It can be a follow-up.Testing
phpunit --testsuite unit: 246 tests pass.phpunit --testsuite integration: 280 tests pass, 42 skipped. I did not investigate the skips.Closes #17 only partly (see "Not covered").
🤖 Generated with Claude Code
https://claude.ai/code/session_018sYJSnbvafWtzadV4wcKZx
Generated by Claude Code