Add support for partitioned cookies
See gh-42316
This commit is contained in:
committed by
Moritz Halbritter
parent
7a176bc205
commit
4a1676d857
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2012-2023 the original author or authors.
|
||||
* Copyright 2012-2024 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -98,6 +98,7 @@ public class SessionAutoConfiguration {
|
||||
map.from(cookie::getSecure).to(cookieSerializer::setUseSecureCookie);
|
||||
map.from(cookie::getMaxAge).asInt(Duration::getSeconds).to(cookieSerializer::setCookieMaxAge);
|
||||
map.from(cookie::getSameSite).as(SameSite::attributeValue).to(cookieSerializer::setSameSite);
|
||||
map.from(cookie::getPartitioned).to(cookieSerializer::setPartitioned);
|
||||
cookieSerializerCustomizers.orderedStream().forEach((customizer) -> customizer.customize(cookieSerializer));
|
||||
return cookieSerializer;
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2012-2022 the original author or authors.
|
||||
* Copyright 2012-2024 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -76,6 +76,7 @@ public class WebSessionIdResolverAutoConfiguration {
|
||||
map.from(cookie::getHttpOnly).to(builder::httpOnly);
|
||||
map.from(cookie::getSecure).to(builder::secure);
|
||||
map.from(cookie::getMaxAge).to(builder::maxAge);
|
||||
map.from(cookie::getPartitioned).to(builder::partitioned);
|
||||
map.from(getSameSite(cookie)).to(builder::sameSite);
|
||||
}
|
||||
|
||||
|
||||
@@ -143,6 +143,10 @@
|
||||
"name": "server.reactive.session.cookie.name",
|
||||
"description": "Name for the cookie."
|
||||
},
|
||||
{
|
||||
"name": "server.reactive.session.cookie.partitioned",
|
||||
"description": "Whether the generated cookie carries the Partitioned attribute."
|
||||
},
|
||||
{
|
||||
"name": "server.reactive.session.cookie.path",
|
||||
"description": "Path of the cookie."
|
||||
@@ -229,6 +233,10 @@
|
||||
"name": "server.servlet.session.cookie.name",
|
||||
"description": "Name of the cookie."
|
||||
},
|
||||
{
|
||||
"name": "server.servlet.session.cookie.partitioned",
|
||||
"description": "Whether the generated cookie carries the Partitioned attribute."
|
||||
},
|
||||
{
|
||||
"name": "server.servlet.session.cookie.path",
|
||||
"description": "Path of the cookie."
|
||||
|
||||
@@ -156,7 +156,7 @@ class SessionAutoConfigurationTests extends AbstractSessionAutoConfigurationTest
|
||||
.withPropertyValues("server.servlet.session.cookie.name=sid", "server.servlet.session.cookie.domain=spring",
|
||||
"server.servlet.session.cookie.path=/test", "server.servlet.session.cookie.httpOnly=false",
|
||||
"server.servlet.session.cookie.secure=false", "server.servlet.session.cookie.maxAge=10s",
|
||||
"server.servlet.session.cookie.sameSite=strict")
|
||||
"server.servlet.session.cookie.sameSite=strict", "server.servlet.session.cookie.partitioned=true")
|
||||
.run((context) -> {
|
||||
DefaultCookieSerializer cookieSerializer = context.getBean(DefaultCookieSerializer.class);
|
||||
assertThat(cookieSerializer).hasFieldOrPropertyWithValue("cookieName", "sid");
|
||||
@@ -166,6 +166,7 @@ class SessionAutoConfigurationTests extends AbstractSessionAutoConfigurationTest
|
||||
assertThat(cookieSerializer).hasFieldOrPropertyWithValue("useSecureCookie", false);
|
||||
assertThat(cookieSerializer).hasFieldOrPropertyWithValue("cookieMaxAge", 10);
|
||||
assertThat(cookieSerializer).hasFieldOrPropertyWithValue("sameSite", "Strict");
|
||||
assertThat(cookieSerializer).hasFieldOrPropertyWithValue("partitioned", true);
|
||||
});
|
||||
}
|
||||
|
||||
|
||||
@@ -644,7 +644,8 @@ class WebFluxAutoConfigurationTests {
|
||||
this.contextRunner.withPropertyValues("server.reactive.session.cookie.name:JSESSIONID",
|
||||
"server.reactive.session.cookie.domain:.example.com", "server.reactive.session.cookie.path:/example",
|
||||
"server.reactive.session.cookie.max-age:60", "server.reactive.session.cookie.http-only:false",
|
||||
"server.reactive.session.cookie.secure:false", "server.reactive.session.cookie.same-site:strict")
|
||||
"server.reactive.session.cookie.secure:false", "server.reactive.session.cookie.same-site:strict",
|
||||
"server.reactive.session.cookie.partitioned:true")
|
||||
.run(assertExchangeWithSession((exchange) -> {
|
||||
List<ResponseCookie> cookies = exchange.getResponse().getCookies().get("JSESSIONID");
|
||||
assertThat(cookies).isNotEmpty();
|
||||
@@ -654,6 +655,7 @@ class WebFluxAutoConfigurationTests {
|
||||
assertThat(cookies).allMatch((cookie) -> !cookie.isHttpOnly());
|
||||
assertThat(cookies).allMatch((cookie) -> !cookie.isSecure());
|
||||
assertThat(cookies).allMatch((cookie) -> cookie.getSameSite().equals("Strict"));
|
||||
assertThat(cookies).allMatch(ResponseCookie::isPartitioned);
|
||||
}));
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user