Rocket/core/lib/tests/session-cookies-issue-1506.rs
Sergio Benitez 4e06ee64aa Test 'secret_key' validation, now on pre-launch.
Prior to this commit, it was not possible to test Rocket crates in
production mode without setting a global secret key or bypassing secret
key checking - the testing script did the latter. The consequence is
that it became impossible to test secret key related failures because
the tests passed regardless.

This commit undoes this. As a consequence, all tests are now aware of
the difference between debug and release configurations, the latter of
which validates 'secret_key' by default. New 'Client::debug()' and
'Client::debug_with()' simplify creating an instance of 'Client' with
configuration in debug mode to avoid undesired test failures.

The summary of changes in this commit are:

  * Config 'secret_key' success and failure are now tested.
  * 'secret_key' validation was moved to pre-launch from 'Config:from()'.
  * 'Config::from()' only extracts the config.
  * Added 'Config::try_from()' for non-panicking extraction.
  * 'Config' now knows the profile it was extracted from.
  * The 'Config' provider sets a profile of 'Config.profile'.
  * 'Rocket', 'Client', 'Fairings', implement 'Debug'.
  * 'fairing::Info' implements 'Copy', 'Clone'.
  * 'Fairings' keeps track of, logs attach fairings.
  * 'Rocket::reconfigure()' was added to allow modifying a config.

Internally, the testing script was refactored to properly test the
codebase with the new changes. In particular, it no longer sets a rustc
'cfg' to avoid secret-key checking.

Resolves #1543.
Fixes #1564.
2021-03-09 21:57:26 -08:00

25 lines
686 B
Rust

#![cfg(feature = "secrets")]
use rocket::http::{CookieJar, Cookie};
#[rocket::get("/")]
fn index(jar: &CookieJar<'_>) {
let session_cookie = Cookie::build("key", "value").expires(None);
jar.add_private(session_cookie.finish());
}
mod test_session_cookies {
use super::*;
use rocket::local::blocking::Client;
#[test]
fn session_cookie_is_session() {
let rocket = rocket::ignite().mount("/", rocket::routes![index]);
let client = Client::debug(rocket).unwrap();
let response = client.get("/").dispatch();
let cookie = response.cookies().get_private("key").unwrap();
assert_eq!(cookie.expires_datetime(), None);
}
}