You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

cookie.go 2.4KB

Move macaron to chi (#14293) Use [chi](https://github.com/go-chi/chi) instead of the forked [macaron](https://gitea.com/macaron/macaron). Since macaron and chi have conflicts with session share, this big PR becomes a have-to thing. According my previous idea, we can replace macaron step by step but I'm wrong. :( Below is a list of big changes on this PR. - [x] Define `context.ResponseWriter` interface with an implementation `context.Response`. - [x] Use chi instead of macaron, and also a customize `Route` to wrap chi so that the router usage is similar as before. - [x] Create different routers for `web`, `api`, `internal` and `install` so that the codes will be more clear and no magic . - [x] Use https://github.com/unrolled/render instead of macaron's internal render - [x] Use https://github.com/NYTimes/gziphandler instead of https://gitea.com/macaron/gzip - [x] Use https://gitea.com/go-chi/session which is a modified version of https://gitea.com/macaron/session and removed `nodb` support since it will not be maintained. **BREAK** - [x] Use https://gitea.com/go-chi/captcha which is a modified version of https://gitea.com/macaron/captcha - [x] Use https://gitea.com/go-chi/cache which is a modified version of https://gitea.com/macaron/cache - [x] Use https://gitea.com/go-chi/binding which is a modified version of https://gitea.com/macaron/binding - [x] Use https://github.com/go-chi/cors instead of https://gitea.com/macaron/cors - [x] Dropped https://gitea.com/macaron/i18n and make a new one in `code.gitea.io/gitea/modules/translation` - [x] Move validation form structs from `code.gitea.io/gitea/modules/auth` to `code.gitea.io/gitea/modules/forms` to avoid dependency cycle. - [x] Removed macaron log service because it's not need any more. **BREAK** - [x] All form structs have to be get by `web.GetForm(ctx)` in the route function but not as a function parameter on routes definition. - [x] Move Git HTTP protocol implementation to use routers directly. - [x] Fix the problem that chi routes don't support trailing slash but macaron did. - [x] `/api/v1/swagger` now will be redirect to `/api/swagger` but not render directly so that `APIContext` will not create a html render. Notices: - Chi router don't support request with trailing slash - Integration test `TestUserHeatmap` maybe mysql version related. It's failed on my macOS(mysql 5.7.29 installed via brew) but succeed on CI. Co-authored-by: 6543 <6543@obermui.de>
3 years ago
Move macaron to chi (#14293) Use [chi](https://github.com/go-chi/chi) instead of the forked [macaron](https://gitea.com/macaron/macaron). Since macaron and chi have conflicts with session share, this big PR becomes a have-to thing. According my previous idea, we can replace macaron step by step but I'm wrong. :( Below is a list of big changes on this PR. - [x] Define `context.ResponseWriter` interface with an implementation `context.Response`. - [x] Use chi instead of macaron, and also a customize `Route` to wrap chi so that the router usage is similar as before. - [x] Create different routers for `web`, `api`, `internal` and `install` so that the codes will be more clear and no magic . - [x] Use https://github.com/unrolled/render instead of macaron's internal render - [x] Use https://github.com/NYTimes/gziphandler instead of https://gitea.com/macaron/gzip - [x] Use https://gitea.com/go-chi/session which is a modified version of https://gitea.com/macaron/session and removed `nodb` support since it will not be maintained. **BREAK** - [x] Use https://gitea.com/go-chi/captcha which is a modified version of https://gitea.com/macaron/captcha - [x] Use https://gitea.com/go-chi/cache which is a modified version of https://gitea.com/macaron/cache - [x] Use https://gitea.com/go-chi/binding which is a modified version of https://gitea.com/macaron/binding - [x] Use https://github.com/go-chi/cors instead of https://gitea.com/macaron/cors - [x] Dropped https://gitea.com/macaron/i18n and make a new one in `code.gitea.io/gitea/modules/translation` - [x] Move validation form structs from `code.gitea.io/gitea/modules/auth` to `code.gitea.io/gitea/modules/forms` to avoid dependency cycle. - [x] Removed macaron log service because it's not need any more. **BREAK** - [x] All form structs have to be get by `web.GetForm(ctx)` in the route function but not as a function parameter on routes definition. - [x] Move Git HTTP protocol implementation to use routers directly. - [x] Fix the problem that chi routes don't support trailing slash but macaron did. - [x] `/api/v1/swagger` now will be redirect to `/api/swagger` but not render directly so that `APIContext` will not create a html render. Notices: - Chi router don't support request with trailing slash - Integration test `TestUserHeatmap` maybe mysql version related. It's failed on my macOS(mysql 5.7.29 installed via brew) but succeed on CI. Co-authored-by: 6543 <6543@obermui.de>
3 years ago
12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576
  1. // Copyright 2020 The Macaron Authors
  2. // Copyright 2020 The Gitea Authors. All rights reserved.
  3. // SPDX-License-Identifier: MIT
  4. package middleware
  5. import (
  6. "net/http"
  7. "net/url"
  8. "strings"
  9. "code.gitea.io/gitea/modules/setting"
  10. )
  11. // SetRedirectToCookie convenience function to set the RedirectTo cookie consistently
  12. func SetRedirectToCookie(resp http.ResponseWriter, value string) {
  13. SetSiteCookie(resp, "redirect_to", value, 0)
  14. }
  15. // DeleteRedirectToCookie convenience function to delete most cookies consistently
  16. func DeleteRedirectToCookie(resp http.ResponseWriter) {
  17. SetSiteCookie(resp, "redirect_to", "", -1)
  18. }
  19. // GetSiteCookie returns given cookie value from request header.
  20. func GetSiteCookie(req *http.Request, name string) string {
  21. cookie, err := req.Cookie(name)
  22. if err != nil {
  23. return ""
  24. }
  25. val, _ := url.QueryUnescape(cookie.Value)
  26. return val
  27. }
  28. // SetSiteCookie returns given cookie value from request header.
  29. func SetSiteCookie(resp http.ResponseWriter, name, value string, maxAge int) {
  30. cookie := &http.Cookie{
  31. Name: name,
  32. Value: url.QueryEscape(value),
  33. MaxAge: maxAge,
  34. Path: setting.SessionConfig.CookiePath,
  35. Domain: setting.SessionConfig.Domain,
  36. Secure: setting.SessionConfig.Secure,
  37. HttpOnly: true,
  38. SameSite: setting.SessionConfig.SameSite,
  39. }
  40. resp.Header().Add("Set-Cookie", cookie.String())
  41. // Previous versions would use a cookie path with a trailing /.
  42. // These are more specific than cookies without a trailing /, so
  43. // we need to delete these if they exist.
  44. DeleteLegacySiteCookie(resp, name)
  45. }
  46. // DeleteLegacySiteCookie deletes the cookie with the given name at the cookie
  47. // path with a trailing /, which would unintentionally override the cookie.
  48. func DeleteLegacySiteCookie(resp http.ResponseWriter, name string) {
  49. if setting.SessionConfig.CookiePath == "" || strings.HasSuffix(setting.SessionConfig.CookiePath, "/") {
  50. // If the cookie path ends with /, no legacy cookies will take
  51. // precedence, so do nothing. The exception is that cookies with no
  52. // path could override other cookies, but it's complicated and we don't
  53. // currently handle that.
  54. return
  55. }
  56. cookie := &http.Cookie{
  57. Name: name,
  58. Value: "",
  59. MaxAge: -1,
  60. Path: setting.SessionConfig.CookiePath + "/",
  61. Domain: setting.SessionConfig.Domain,
  62. Secure: setting.SessionConfig.Secure,
  63. HttpOnly: true,
  64. SameSite: setting.SessionConfig.SameSite,
  65. }
  66. resp.Header().Add("Set-Cookie", cookie.String())
  67. }