From 33cbe7654c9e04a9e176c246ae66c7b1e15100cb Mon Sep 17 00:00:00 2001 From: mo khan Date: Wed, 7 May 2025 10:55:44 -0700 Subject: fix: use same site lax mode to allow setting cooking on redirect --- app/controllers/sessions/controller.go | 7 ++++++- app/controllers/sessions/controller_test.go | 2 +- 2 files changed, 7 insertions(+), 2 deletions(-) (limited to 'app') diff --git a/app/controllers/sessions/controller.go b/app/controllers/sessions/controller.go index 77a30fd..5681f65 100644 --- a/app/controllers/sessions/controller.go +++ b/app/controllers/sessions/controller.go @@ -139,7 +139,12 @@ func (c *Controller) Create(w http.ResponseWriter, r *http.Request) { return } - cookie.Write(w, web.NewCookie("session", encoded, cookie.WithExpiration(tokens.Expiry))) + cookie.Write(w, web.NewCookie( + "session", + encoded, + cookie.WithExpiration(tokens.Expiry), + cookie.WithSameSite(http.SameSiteLaxMode), + )) http.Redirect(w, r, "/dashboard", http.StatusFound) } diff --git a/app/controllers/sessions/controller_test.go b/app/controllers/sessions/controller_test.go index a1158da..43cd0b9 100644 --- a/app/controllers/sessions/controller_test.go +++ b/app/controllers/sessions/controller_test.go @@ -156,7 +156,7 @@ func TestSessions(t *testing.T) { assert.Equal(t, "/", cookie.Path) assert.Equal(t, "localhost", cookie.Domain) assert.Equal(t, "session", cookie.Name) - assert.Zero(t, cookie.SameSite) + assert.Equal(t, http.SameSiteLaxMode, cookie.SameSite) assert.Equal(t, x.Must(time.Parse(time.RFC3339, tokens["expiry"].(string))).Unix(), cookie.Expires.Unix()) assert.True(t, cookie.HttpOnly) assert.True(t, cookie.Secure) -- cgit v1.2.3