Add Partitioned cookie attribute support for servers

This commit adds support for the "Partitioned" cookie attribute in
WebFlux servers and the related testing infrastructure.
Note, Undertow does not support this feature at the moment.

Closes gh-31454
This commit is contained in:
Brian Clozel
2024-06-07 10:03:52 +02:00
parent 2aabe238c6
commit 7fc4937199
18 changed files with 178 additions and 10 deletions

View File

@@ -98,6 +98,24 @@ public class MockCookie extends Cookie {
return getAttribute(SAME_SITE);
}
/**
* Set the "Partitioned" attribute for this cookie.
* @since 6.2
* @see <a href="https://datatracker.ietf.org/doc/html/draft-cutler-httpbis-partitioned-cookies#section-2.1">The Partitioned attribute spec</a>
*/
public void setPartitioned(boolean partitioned) {
setAttribute("Partitioned", "");
}
/**
* Return whether the "Partitioned" attribute is set for this cookie.
* @since 6.2
* @see <a href="https://datatracker.ietf.org/doc/html/draft-cutler-httpbis-partitioned-cookies#section-2.1">The Partitioned attribute spec</a>
*/
public boolean isPartitioned() {
return getAttribute("Partitioned") != null;
}
/**
* Factory method that parses the value of the supplied "Set-Cookie" header.
* @param setCookieHeader the "Set-Cookie" value; never {@code null} or empty
@@ -146,6 +164,9 @@ public class MockCookie extends Cookie {
else if (StringUtils.startsWithIgnoreCase(attribute, "Comment")) {
cookie.setComment(extractAttributeValue(attribute, setCookieHeader));
}
else if (!attribute.isEmpty()) {
cookie.setAttribute(attribute, extractOptionalAttributeValue(attribute, setCookieHeader));
}
}
return cookie;
}
@@ -157,6 +178,11 @@ public class MockCookie extends Cookie {
return nameAndValue[1];
}
private static String extractOptionalAttributeValue(String attribute, String header) {
String[] nameAndValue = attribute.split("=");
return nameAndValue.length == 2 ? nameAndValue[1] : "";
}
@Override
public void setAttribute(String name, @Nullable String value) {
if (EXPIRES.equalsIgnoreCase(name)) {
@@ -176,6 +202,7 @@ public class MockCookie extends Cookie {
.append("Comment", getComment())
.append("Secure", getSecure())
.append("HttpOnly", isHttpOnly())
.append("Partitioned", isPartitioned())
.append(SAME_SITE, getSameSite())
.append("Max-Age", getMaxAge())
.append(EXPIRES, getAttribute(EXPIRES))

View File

@@ -481,6 +481,9 @@ public class MockHttpServletResponse implements HttpServletResponse {
if (cookie.isHttpOnly()) {
buf.append("; HttpOnly");
}
if (cookie.getAttribute("Partitioned") != null) {
buf.append("; Partitioned");
}
if (cookie instanceof MockCookie mockCookie) {
if (StringUtils.hasText(mockCookie.getSameSite())) {
buf.append("; SameSite=").append(mockCookie.getSameSite());

View File

@@ -197,6 +197,19 @@ public class CookieAssertions {
return this.responseSpec;
}
/**
* Assert a cookie's "Partitioned" attribute.
* @since 6.2
*/
public WebTestClient.ResponseSpec partitioned(String name, boolean expected) {
boolean isPartitioned = getCookie(name).isPartitioned();
this.exchangeResult.assertWithDiagnostics(() -> {
String message = getMessage(name) + " isPartitioned";
assertEquals(message, expected, isPartitioned);
});
return this.responseSpec;
}
/**
* Assert a cookie's "SameSite" attribute.
*/

View File

@@ -209,6 +209,7 @@ public class MockMvcHttpConnector implements ClientHttpConnector {
.path(cookie.getPath())
.secure(cookie.getSecure())
.httpOnly(cookie.isHttpOnly())
.partitioned(cookie.getAttribute("Partitioned") != null)
.sameSite(cookie.getAttribute("samesite"))
.build();
clientResponse.getCookies().add(httpCookie.getName(), httpCookie);

View File

@@ -1,5 +1,5 @@
/*
* Copyright 2002-2023 the original author or authors.
* Copyright 2002-2024 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@@ -229,6 +229,17 @@ public class CookieResultMatchers {
};
}
/**
* Assert whether the cookie is partitioned.
* @since 6.2
*/
public ResultMatcher partitioned(String name, boolean partitioned) {
return result -> {
Cookie cookie = getCookie(result, name);
assertEquals("Response cookie '" + name + "' partitioned", partitioned, cookie.getAttribute("Partitioned") != null);
};
}
/**
* Assert a cookie's specified attribute with a Hamcrest {@link Matcher}.
* @param cookieAttribute the name of the Cookie attribute (case-insensitive)

View File

@@ -157,6 +157,14 @@ class CookieResultMatchersDsl internal constructor (private val actions: ResultA
actions.andExpect(matchers.httpOnly(name, httpOnly))
}
/**
* @see CookieResultMatchers.partitioned
* @since 6.2
*/
fun partitioned(name: String, partitioned: Boolean) {
actions.andExpect(matchers.partitioned(name, partitioned))
}
/**
* @see CookieResultMatchers.attribute
* @since 6.0.8

View File

@@ -71,7 +71,7 @@ class MockCookieTests {
@Test
void parseHeaderWithAttributes() {
MockCookie cookie = MockCookie.parse("SESSION=123; Domain=example.com; Max-Age=60; " +
"Expires=Tue, 8 Oct 2019 19:50:00 GMT; Path=/; Secure; HttpOnly; SameSite=Lax");
"Expires=Tue, 8 Oct 2019 19:50:00 GMT; Path=/; Secure; HttpOnly; Partitioned; SameSite=Lax");
assertCookie(cookie, "SESSION", "123");
assertThat(cookie.getDomain()).isEqualTo("example.com");
@@ -79,6 +79,7 @@ class MockCookieTests {
assertThat(cookie.getPath()).isEqualTo("/");
assertThat(cookie.getSecure()).isTrue();
assertThat(cookie.isHttpOnly()).isTrue();
assertThat(cookie.isPartitioned()).isTrue();
assertThat(cookie.getExpires()).isEqualTo(ZonedDateTime.parse("Tue, 8 Oct 2019 19:50:00 GMT",
DateTimeFormatter.RFC_1123_DATE_TIME));
assertThat(cookie.getSameSite()).isEqualTo("Lax");
@@ -203,4 +204,12 @@ class MockCookieTests {
assertThatThrownBy(() -> cookie.setAttribute("expires", "12345")).isInstanceOf(DateTimeParseException.class);
}
@Test
void setPartitioned() {
MockCookie cookie = new MockCookie("SESSION", "123");
cookie.setAttribute("Partitioned", "");
assertThat(cookie.isPartitioned()).isTrue();
}
}

View File

@@ -274,12 +274,13 @@ class MockHttpServletResponseTests {
cookie.setMaxAge(0);
cookie.setSecure(true);
cookie.setHttpOnly(true);
cookie.setAttribute("Partitioned", "");
response.addCookie(cookie);
assertThat(response.getHeader(SET_COOKIE)).isEqualTo(("foo=bar; Path=/path; Domain=example.com; " +
"Max-Age=0; Expires=Thu, 01 Jan 1970 00:00:00 GMT; " +
"Secure; HttpOnly"));
"Secure; HttpOnly; Partitioned"));
}
@Test

View File

@@ -37,7 +37,7 @@ import static org.mockito.Mockito.mock;
*
* @author Rossen Stoyanchev
*/
public class CookieAssertionTests {
public class CookieAssertionsTests {
private final ResponseCookie cookie = ResponseCookie.from("foo", "bar")
.maxAge(Duration.ofMinutes(30))
@@ -45,6 +45,7 @@ public class CookieAssertionTests {
.path("/foo")
.secure(true)
.httpOnly(true)
.partitioned(true)
.sameSite("Lax")
.build();
@@ -117,6 +118,12 @@ public class CookieAssertionTests {
assertThatExceptionOfType(AssertionError.class).isThrownBy(() -> assertions.httpOnly("foo", false));
}
@Test
void partitioned() {
assertions.partitioned("foo", true);
assertThatExceptionOfType(AssertionError.class).isThrownBy(() -> assertions.partitioned("foo", false));
}
@Test
void sameSite() {
assertions.sameSite("foo", "Lax");