2008-05-17 23:22:34 -05:00
|
|
|
require 'abstract_unit'
|
2007-01-22 07:43:50 -06:00
|
|
|
|
2009-02-04 14:26:08 -06:00
|
|
|
class CookieTest < ActionController::TestCase
|
2007-01-22 07:43:50 -06:00
|
|
|
class TestController < ActionController::Base
|
2010-05-25 12:45:45 -05:00
|
|
|
self.cookie_verifier_secret = "thisISverySECRET123"
|
|
|
|
|
2007-01-22 07:43:50 -06:00
|
|
|
def authenticate
|
|
|
|
cookies["user_name"] = "david"
|
|
|
|
end
|
|
|
|
|
2009-08-04 10:16:03 -05:00
|
|
|
def set_with_with_escapable_characters
|
|
|
|
cookies["that & guy"] = "foo & bar => baz"
|
|
|
|
end
|
|
|
|
|
2007-12-21 01:48:59 -06:00
|
|
|
def authenticate_for_fourteen_days
|
2009-02-04 14:26:08 -06:00
|
|
|
cookies["user_name"] = { "value" => "david", "expires" => Time.utc(2005, 10, 10,5) }
|
2007-01-22 07:43:50 -06:00
|
|
|
end
|
|
|
|
|
2007-12-21 01:48:59 -06:00
|
|
|
def authenticate_for_fourteen_days_with_symbols
|
2009-02-04 14:26:08 -06:00
|
|
|
cookies[:user_name] = { :value => "david", :expires => Time.utc(2005, 10, 10,5) }
|
2007-01-22 07:43:50 -06:00
|
|
|
end
|
|
|
|
|
|
|
|
def set_multiple_cookies
|
2009-02-04 14:26:08 -06:00
|
|
|
cookies["user_name"] = { "value" => "david", "expires" => Time.utc(2005, 10, 10,5) }
|
2007-01-22 07:43:50 -06:00
|
|
|
cookies["login"] = "XJ-122"
|
|
|
|
end
|
2009-02-04 14:26:08 -06:00
|
|
|
|
2007-01-22 07:43:50 -06:00
|
|
|
def access_frozen_cookies
|
2007-02-09 02:04:31 -06:00
|
|
|
cookies["will"] = "work"
|
2007-01-22 07:43:50 -06:00
|
|
|
end
|
|
|
|
|
2007-02-09 02:04:31 -06:00
|
|
|
def logout
|
|
|
|
cookies.delete("user_name")
|
|
|
|
end
|
|
|
|
|
2007-10-15 12:16:54 -05:00
|
|
|
def delete_cookie_with_path
|
|
|
|
cookies.delete("user_name", :path => '/beaten')
|
2007-12-21 01:48:59 -06:00
|
|
|
render :text => "hello world"
|
|
|
|
end
|
|
|
|
|
|
|
|
def authenticate_with_http_only
|
2009-02-27 19:23:00 -06:00
|
|
|
cookies["user_name"] = { :value => "david", :httponly => true }
|
2007-10-15 12:16:54 -05:00
|
|
|
end
|
2010-05-25 12:45:45 -05:00
|
|
|
|
2010-10-15 10:47:59 -05:00
|
|
|
def authenticate_with_secure
|
|
|
|
cookies["user_name"] = { :value => "david", :secure => true }
|
|
|
|
end
|
|
|
|
|
2010-05-25 12:45:45 -05:00
|
|
|
def set_permanent_cookie
|
|
|
|
cookies.permanent[:user_name] = "Jamie"
|
|
|
|
end
|
|
|
|
|
|
|
|
def set_signed_cookie
|
|
|
|
cookies.signed[:user_id] = 45
|
|
|
|
end
|
|
|
|
|
|
|
|
def set_permanent_signed_cookie
|
|
|
|
cookies.permanent.signed[:remember_me] = 100
|
|
|
|
end
|
2007-10-15 12:16:54 -05:00
|
|
|
|
2009-02-04 14:26:08 -06:00
|
|
|
def rescue_action(e)
|
|
|
|
raise unless ActionView::MissingTemplate # No templates here, and we don't care about the output
|
2007-02-09 02:04:31 -06:00
|
|
|
end
|
2007-01-22 07:43:50 -06:00
|
|
|
end
|
|
|
|
|
2009-02-04 14:26:08 -06:00
|
|
|
tests TestController
|
2007-01-22 07:43:50 -06:00
|
|
|
|
2009-02-04 14:26:08 -06:00
|
|
|
def setup
|
2007-01-22 07:43:50 -06:00
|
|
|
@request.host = "www.nextangle.com"
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_setting_cookie
|
2007-02-09 02:04:31 -06:00
|
|
|
get :authenticate
|
2009-02-04 14:26:08 -06:00
|
|
|
assert_equal ["user_name=david; path=/"], @response.headers["Set-Cookie"]
|
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
2007-01-22 07:43:50 -06:00
|
|
|
end
|
|
|
|
|
2009-08-04 10:16:03 -05:00
|
|
|
def test_setting_with_escapable_characters
|
|
|
|
get :set_with_with_escapable_characters
|
|
|
|
assert_equal ["that+%26+guy=foo+%26+bar+%3D%3E+baz; path=/"], @response.headers["Set-Cookie"]
|
|
|
|
assert_equal({"that & guy" => "foo & bar => baz"}, @response.cookies)
|
|
|
|
end
|
|
|
|
|
2007-01-22 07:43:50 -06:00
|
|
|
def test_setting_cookie_for_fourteen_days
|
2007-12-21 01:48:59 -06:00
|
|
|
get :authenticate_for_fourteen_days
|
2009-02-04 14:26:08 -06:00
|
|
|
assert_equal ["user_name=david; path=/; expires=Mon, 10-Oct-2005 05:00:00 GMT"], @response.headers["Set-Cookie"]
|
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
2007-01-22 07:43:50 -06:00
|
|
|
end
|
|
|
|
|
|
|
|
def test_setting_cookie_for_fourteen_days_with_symbols
|
2008-10-27 01:47:01 -05:00
|
|
|
get :authenticate_for_fourteen_days_with_symbols
|
2009-02-04 14:26:08 -06:00
|
|
|
assert_equal ["user_name=david; path=/; expires=Mon, 10-Oct-2005 05:00:00 GMT"], @response.headers["Set-Cookie"]
|
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
2007-01-22 07:43:50 -06:00
|
|
|
end
|
|
|
|
|
2007-12-21 01:48:59 -06:00
|
|
|
def test_setting_cookie_with_http_only
|
|
|
|
get :authenticate_with_http_only
|
2009-02-04 14:26:08 -06:00
|
|
|
assert_equal ["user_name=david; path=/; HttpOnly"], @response.headers["Set-Cookie"]
|
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
2007-12-21 01:48:59 -06:00
|
|
|
end
|
2010-10-15 10:47:59 -05:00
|
|
|
|
|
|
|
def test_setting_cookie_with_secure
|
2011-02-18 23:36:23 -06:00
|
|
|
@request.env["HTTPS"] = "on"
|
2010-10-15 10:47:59 -05:00
|
|
|
get :authenticate_with_secure
|
|
|
|
assert_equal ["user_name=david; path=/; secure"], @response.headers["Set-Cookie"]
|
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
|
|
|
end
|
2007-12-21 01:48:59 -06:00
|
|
|
|
2011-02-18 23:36:23 -06:00
|
|
|
def test_setting_cookie_with_secure_in_development
|
|
|
|
with_environment(:development) do
|
|
|
|
get :authenticate_with_secure
|
|
|
|
assert_equal ["user_name=david; path=/; secure"], @response.headers["Set-Cookie"]
|
|
|
|
assert_equal({"user_name" => "david"}, @response.cookies)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_not_setting_cookie_with_secure
|
|
|
|
get :authenticate_with_secure
|
|
|
|
assert_not_equal ["user_name=david; path=/; secure"], @response.headers["Set-Cookie"]
|
|
|
|
assert_not_equal({"user_name" => "david"}, @response.cookies)
|
|
|
|
end
|
|
|
|
|
2007-01-22 07:43:50 -06:00
|
|
|
def test_multiple_cookies
|
2007-02-09 02:04:31 -06:00
|
|
|
get :set_multiple_cookies
|
|
|
|
assert_equal 2, @response.cookies.size
|
2009-02-04 14:26:08 -06:00
|
|
|
assert_equal "user_name=david; path=/; expires=Mon, 10-Oct-2005 05:00:00 GMT", @response.headers["Set-Cookie"][0]
|
|
|
|
assert_equal "login=XJ-122; path=/", @response.headers["Set-Cookie"][1]
|
|
|
|
assert_equal({"login" => "XJ-122", "user_name" => "david"}, @response.cookies)
|
2007-01-22 07:43:50 -06:00
|
|
|
end
|
|
|
|
|
|
|
|
def test_setting_test_cookie
|
2007-02-09 02:04:31 -06:00
|
|
|
assert_nothing_raised { get :access_frozen_cookies }
|
|
|
|
end
|
2009-02-04 14:26:08 -06:00
|
|
|
|
2007-02-09 02:04:31 -06:00
|
|
|
def test_expiring_cookie
|
|
|
|
get :logout
|
2009-02-04 14:26:08 -06:00
|
|
|
assert_equal ["user_name=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT"], @response.headers["Set-Cookie"]
|
|
|
|
assert_equal({"user_name" => nil}, @response.cookies)
|
|
|
|
end
|
|
|
|
|
2007-02-09 02:04:31 -06:00
|
|
|
def test_cookiejar_accessor
|
2009-02-04 14:26:08 -06:00
|
|
|
@request.cookies["user_name"] = "david"
|
2007-02-09 02:04:31 -06:00
|
|
|
@controller.request = @request
|
|
|
|
jar = ActionController::CookieJar.new(@controller)
|
|
|
|
assert_equal "david", jar["user_name"]
|
|
|
|
assert_equal nil, jar["something_else"]
|
2007-01-22 07:43:50 -06:00
|
|
|
end
|
2007-10-15 12:16:54 -05:00
|
|
|
|
2007-12-21 01:48:59 -06:00
|
|
|
def test_cookiejar_accessor_with_array_value
|
2009-02-04 14:26:08 -06:00
|
|
|
@request.cookies["pages"] = %w{1 2 3}
|
2007-12-21 01:48:59 -06:00
|
|
|
@controller.request = @request
|
|
|
|
jar = ActionController::CookieJar.new(@controller)
|
2009-02-04 14:26:08 -06:00
|
|
|
assert_equal %w{1 2 3}, jar["pages"]
|
2007-12-21 01:48:59 -06:00
|
|
|
end
|
2009-02-04 14:26:08 -06:00
|
|
|
|
2009-11-30 19:38:34 -06:00
|
|
|
def test_cookiejar_delete_removes_item_and_returns_its_value
|
|
|
|
@request.cookies["user_name"] = "david"
|
|
|
|
@controller.response = @response
|
|
|
|
jar = ActionController::CookieJar.new(@controller)
|
|
|
|
assert_equal "david", jar.delete("user_name")
|
|
|
|
end
|
|
|
|
|
2007-10-15 12:16:54 -05:00
|
|
|
def test_delete_cookie_with_path
|
|
|
|
get :delete_cookie_with_path
|
2009-02-04 14:26:08 -06:00
|
|
|
assert_equal ["user_name=; path=/beaten; expires=Thu, 01-Jan-1970 00:00:00 GMT"], @response.headers["Set-Cookie"]
|
2008-06-02 01:35:38 -05:00
|
|
|
end
|
2009-09-05 02:01:46 -05:00
|
|
|
|
|
|
|
def test_cookies_persist_throughout_request
|
|
|
|
get :authenticate
|
|
|
|
cookies = @controller.send(:cookies)
|
|
|
|
assert_equal 'david', cookies['user_name']
|
|
|
|
end
|
2010-05-25 12:45:45 -05:00
|
|
|
|
|
|
|
def test_permanent_cookie
|
|
|
|
get :set_permanent_cookie
|
|
|
|
assert_match /Jamie/, @response.headers["Set-Cookie"].first
|
|
|
|
assert_match %r(#{20.years.from_now.year}), @response.headers["Set-Cookie"].first
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_signed_cookie
|
|
|
|
get :set_signed_cookie
|
|
|
|
assert_equal 45, @controller.send(:cookies).signed[:user_id]
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_accessing_nonexistant_signed_cookie_should_not_raise_an_invalid_signature
|
|
|
|
get :set_signed_cookie
|
|
|
|
assert_nil @controller.send(:cookies).signed[:non_existant_attribute]
|
|
|
|
end
|
|
|
|
|
|
|
|
def test_permanent_signed_cookie
|
|
|
|
get :set_permanent_signed_cookie
|
|
|
|
assert_match %r(#{20.years.from_now.year}), @response.headers["Set-Cookie"].first
|
|
|
|
assert_equal 100, @controller.send(:cookies).signed[:remember_me]
|
|
|
|
end
|
2011-02-18 23:36:23 -06:00
|
|
|
|
|
|
|
private
|
|
|
|
def with_environment(enviroment)
|
|
|
|
old_rails = Object.const_get(:Rails) rescue nil
|
|
|
|
mod = Object.const_set(:Rails, Module.new)
|
|
|
|
(class << mod; self; end).instance_eval do
|
|
|
|
define_method(:env) { @_env ||= ActiveSupport::StringInquirer.new(enviroment.to_s) }
|
|
|
|
end
|
|
|
|
yield
|
|
|
|
ensure
|
|
|
|
Object.module_eval { remove_const(:Rails) } if defined?(Rails)
|
|
|
|
Object.const_set(:Rails, old_rails) if old_rails
|
|
|
|
end
|
2010-05-25 12:45:45 -05:00
|
|
|
end
|