Skip to content

Test the Secure flag of the session cookie - #26

Merged
codeling merged 1 commit into
mainfrom
claude/session-cookie-secure-flag-tests
Oct 3, 2026
Merged

codeling merged 1 commit into
mainfrom
claude/session-cookie-secure-flag-tests

Conversation

@codeling

@codeling codeling commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Summary

Adds automated tests for the Secure flag of the session cookie (issue #17), using the cheaper option from the issue instead of TLS in the web server tests.

  • Moves the cookie parameters from auth.php into sessionCookieParams() / isHttpsRequest() in auth_functions.php. Behaviour is unchanged.
  • Unit tests for HTTPS = on, 1, off, empty and unset. They also check that HttpOnly, SameSite=Lax and the path are always set.
  • Reverse proxies: X-Forwarded-Proto stays untrusted, because any client can send it. Behind a TLS-terminating proxy the cookie therefore never gets Secure. This is documented in the function comment, and no trusted-proxies setting is added.
  • An integration test sends forged X-Forwarded-Proto / X-Forwarded-Ssl headers over plain HTTP and checks that no Secure flag is set. HttpClient::get() gained optional request headers for this.

Not covered

The curl check against Apache (mod_ssl) and nginx with a self-signed certificate in tests/Server/run.sh is not done. It can be a follow-up.

Testing

  • phpunit --testsuite unit: 246 tests pass.
  • phpunit --testsuite integration: 280 tests pass, 42 skipped. I did not investigate the skips.
  • The server suite was not run.

Closes #17 only partly (see "Not covered").

🤖 Generated with Claude Code

https://claude.ai/code/session_018sYJSnbvafWtzadV4wcKZx


Generated by Claude Code

Move the cookie parameters into sessionCookieParams() and unit test them for
HTTPS on/off/empty/unset/1. X-Forwarded-Proto is deliberately not trusted;
an integration test checks that the header does not set the Secure flag.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018sYJSnbvafWtzadV4wcKZx
@codeling
codeling merged commit 39c3ba1 into main Oct 3, 2026
15 checks passed
@codeling
codeling deleted the claude/session-cookie-secure-flag-tests branch October 5, 2026 15:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Automated tests for the Secure flag of the session cookie over HTTPS

2 participants