feat: Session-Cookie secure-Flag per FB_SESSION_COOKIE_SECURE
This commit is contained in:
@@ -1,3 +1,6 @@
|
||||
from app.config import get_settings
|
||||
|
||||
|
||||
def test_api_requires_key(client):
|
||||
assert client.get("/api/accounts").status_code == 401
|
||||
r = client.get("/api/accounts", headers={"Authorization": "Bearer test-key"})
|
||||
@@ -60,3 +63,21 @@ def test_current_password_hash_cache_invalidates_on_file_change(
|
||||
second = current_password_hash()
|
||||
assert second == new_hash
|
||||
assert verify_password("andereswort999", second)
|
||||
|
||||
|
||||
def test_login_cookie_secure_when_enabled(client, monkeypatch):
|
||||
monkeypatch.setenv("FB_SESSION_COOKIE_SECURE", "true")
|
||||
get_settings.cache_clear()
|
||||
r = client.post("/login", data={"username": "admin", "password": "geheim"},
|
||||
follow_redirects=False)
|
||||
assert r.status_code == 303
|
||||
assert "secure" in r.headers["set-cookie"].lower()
|
||||
|
||||
|
||||
def test_login_cookie_not_secure_by_default(client, monkeypatch):
|
||||
monkeypatch.delenv("FB_SESSION_COOKIE_SECURE", raising=False)
|
||||
get_settings.cache_clear()
|
||||
r = client.post("/login", data={"username": "admin", "password": "geheim"},
|
||||
follow_redirects=False)
|
||||
assert r.status_code == 303
|
||||
assert "secure" not in r.headers["set-cookie"].lower()
|
||||
|
||||
Reference in New Issue
Block a user