cookies_test.rb 16.5 KB
Newer Older
1
require 'abstract_unit'
D
Initial  
David Heinemeier Hansson 已提交
2

3
class CookiesTest < ActionController::TestCase
D
Initial  
David Heinemeier Hansson 已提交
4
  class TestController < ActionController::Base
5 6
    def authenticate
      cookies["user_name"] = "david"
J
Jeremy Kemper 已提交
7
      head :ok
8 9
    end

10 11
    def set_with_with_escapable_characters
      cookies["that & guy"] = "foo & bar => baz"
J
Jeremy Kemper 已提交
12
      head :ok
13 14
    end

15
    def authenticate_for_fourteen_days
F
Frederick Cheung 已提交
16
      cookies["user_name"] = { "value" => "david", "expires" => Time.utc(2005, 10, 10,5) }
J
Jeremy Kemper 已提交
17
      head :ok
18 19
    end

20
    def authenticate_for_fourteen_days_with_symbols
F
Frederick Cheung 已提交
21
      cookies[:user_name] = { :value => "david", :expires => Time.utc(2005, 10, 10,5) }
J
Jeremy Kemper 已提交
22
      head :ok
23 24
    end

25
    def set_multiple_cookies
F
Frederick Cheung 已提交
26
      cookies["user_name"] = { "value" => "david", "expires" => Time.utc(2005, 10, 10,5) }
27
      cookies["login"]     = "XJ-122"
J
Jeremy Kemper 已提交
28
      head :ok
29
    end
J
Joshua Peek 已提交
30

31
    def access_frozen_cookies
J
Jeremy Kemper 已提交
32
      cookies["will"] = "work"
J
Jeremy Kemper 已提交
33
      head :ok
34 35
    end

36 37
    def logout
      cookies.delete("user_name")
J
Jeremy Kemper 已提交
38
      head :ok
39 40
    end

41 42
    def delete_cookie_with_path
      cookies.delete("user_name", :path => '/beaten')
J
Jeremy Kemper 已提交
43
      head :ok
44 45
    end

46
    def authenticate_with_http_only
47
      cookies["user_name"] = { :value => "david", :httponly => true }
J
Jeremy Kemper 已提交
48
      head :ok
49
    end
50

51 52 53 54
    def authenticate_with_secure
      cookies["user_name"] = { :value => "david", :secure => true }
      head :ok
    end
55 56 57 58 59

    def set_permanent_cookie
      cookies.permanent[:user_name] = "Jamie"
      head :ok
    end
J
Joshua Peek 已提交
60

61 62 63 64
    def set_signed_cookie
      cookies.signed[:user_id] = 45
      head :ok
    end
J
Joshua Peek 已提交
65

66 67 68 69 70 71 72 73 74 75 76
    def raise_data_overflow
      cookies.signed[:foo] = 'bye!' * 1024
      head :ok
    end

    def tampered_cookies
      cookies[:tampered] = "BAh7BjoIZm9vIghiYXI%3D--123456780"
      cookies.signed[:tampered]
      head :ok
    end

77 78 79 80
    def set_permanent_signed_cookie
      cookies.permanent.signed[:remember_me] = 100
      head :ok
    end
81 82 83 84 85 86

    def delete_and_set_cookie
      cookies.delete :user_name
      cookies[:user_name] = { :value => "david", :expires => Time.utc(2005, 10, 10,5) }
      head :ok
    end
87 88 89 90 91 92 93 94 95 96

    def set_cookie_with_domain
      cookies[:user_name] = {:value => "rizwanreza", :domain => :all}
      head :ok
    end

    def delete_cookie_with_domain
      cookies.delete(:user_name, :domain => :all)
      head :ok
    end
97

98 99 100 101 102 103 104 105 106 107
    def set_cookie_with_domain_and_tld
      cookies[:user_name] = {:value => "rizwanreza", :domain => :all, :tld_length => 2}
      head :ok
    end

    def delete_cookie_with_domain_and_tld
      cookies.delete(:user_name, :domain => :all, :tld_length => 2)
      head :ok
    end

108 109 110 111 112 113 114 115 116 117
    def set_cookie_with_domains
      cookies[:user_name] = {:value => "rizwanreza", :domain => %w(example1.com example2.com .example3.com)}
      head :ok
    end

    def delete_cookie_with_domains
      cookies.delete(:user_name, :domain => %w(example1.com example2.com .example3.com))
      head :ok
    end

118 119 120 121 122 123
    def symbol_key
      cookies[:user_name] = "david"
      head :ok
    end

    def string_key
S
steve 已提交
124
      cookies['user_name'] = "dhh"
125 126
      head :ok
    end
127 128 129 130 131 132 133 134 135 136 137 138 139 140

    def symbol_key_mock
      cookies[:user_name] = "david" if cookies[:user_name] == "andrew"
      head :ok
    end

    def string_key_mock
      cookies['user_name'] = "david" if cookies['user_name'] == "andrew"
      head :ok
    end

    def noop
      head :ok
    end
D
Initial  
David Heinemeier Hansson 已提交
141 142
  end

143
  tests TestController
D
Initial  
David Heinemeier Hansson 已提交
144

145
  def setup
146
    super
147
    @request.env["action_dispatch.secret_token"] = "b3c631c314c0bbca50c1b2843150fe33"
D
Initial  
David Heinemeier Hansson 已提交
148 149 150
    @request.host = "www.nextangle.com"
  end

151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166
  def test_each
    request.cookie_jar['foo'] = :bar
    list = []
    request.cookie_jar.each do |k,v|
      list << [k, v]
    end

    assert_equal [['foo', :bar]], list
  end

  def test_enumerable
    request.cookie_jar['foo'] = :bar
    actual = request.cookie_jar.map { |k,v| [k.to_s, v.to_s] }
    assert_equal [['foo', 'bar']], actual
  end

167 168 169 170 171 172 173 174 175
  def test_key_methods
    assert !request.cookie_jar.key?(:foo)
    assert !request.cookie_jar.has_key?("foo")

    request.cookie_jar[:foo] = :bar
    assert request.cookie_jar.key?(:foo)
    assert request.cookie_jar.has_key?("foo")
  end

D
Initial  
David Heinemeier Hansson 已提交
176
  def test_setting_cookie
177
    get :authenticate
J
Jeremy Kemper 已提交
178
    assert_cookie_header "user_name=david; path=/"
179
    assert_equal({"user_name" => "david"}, @response.cookies)
D
Initial  
David Heinemeier Hansson 已提交
180 181
  end

182 183
  def test_setting_with_escapable_characters
    get :set_with_with_escapable_characters
J
Jeremy Kemper 已提交
184
    assert_cookie_header "that+%26+guy=foo+%26+bar+%3D%3E+baz; path=/"
185 186 187
    assert_equal({"that & guy" => "foo & bar => baz"}, @response.cookies)
  end

188
  def test_setting_cookie_for_fourteen_days
189
    get :authenticate_for_fourteen_days
J
Jeremy Kemper 已提交
190
    assert_cookie_header "user_name=david; path=/; expires=Mon, 10-Oct-2005 05:00:00 GMT"
191
    assert_equal({"user_name" => "david"}, @response.cookies)
192
  end
193

194
  def test_setting_cookie_for_fourteen_days_with_symbols
P
Pratik Naik 已提交
195
    get :authenticate_for_fourteen_days_with_symbols
J
Jeremy Kemper 已提交
196
    assert_cookie_header "user_name=david; path=/; expires=Mon, 10-Oct-2005 05:00:00 GMT"
197
    assert_equal({"user_name" => "david"}, @response.cookies)
198 199
  end

200 201
  def test_setting_cookie_with_http_only
    get :authenticate_with_http_only
J
Jeremy Kemper 已提交
202
    assert_cookie_header "user_name=david; path=/; HttpOnly"
203
    assert_equal({"user_name" => "david"}, @response.cookies)
204
  end
205

206
  def test_setting_cookie_with_secure
207
    @request.env["HTTPS"] = "on"
208 209 210 211
    get :authenticate_with_secure
    assert_cookie_header "user_name=david; path=/; secure"
    assert_equal({"user_name" => "david"}, @response.cookies)
  end
212

L
lest 已提交
213 214
  def test_setting_cookie_with_secure_when_always_write_cookie_is_true
    ActionDispatch::Cookies::CookieJar.any_instance.stubs(:always_write_cookie).returns(true)
215 216 217 218 219 220 221 222 223 224 225
    get :authenticate_with_secure
    assert_cookie_header "user_name=david; path=/; secure"
    assert_equal({"user_name" => "david"}, @response.cookies)
  end

  def test_not_setting_cookie_with_secure
    get :authenticate_with_secure
    assert_not_cookie_header "user_name=david; path=/; secure"
    assert_not_equal({"user_name" => "david"}, @response.cookies)
  end

226
  def test_multiple_cookies
227 228
    get :set_multiple_cookies
    assert_equal 2, @response.cookies.size
J
Jeremy Kemper 已提交
229
    assert_cookie_header "user_name=david; path=/; expires=Mon, 10-Oct-2005 05:00:00 GMT\nlogin=XJ-122; path=/"
230
    assert_equal({"login" => "XJ-122", "user_name" => "david"}, @response.cookies)
231
  end
232

233
  def test_setting_test_cookie
234 235
    assert_nothing_raised { get :access_frozen_cookies }
  end
J
Joshua Peek 已提交
236

237 238
  def test_expiring_cookie
    get :logout
J
Jeremy Kemper 已提交
239
    assert_cookie_header "user_name=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT"
240
    assert_equal({"user_name" => nil}, @response.cookies)
241
  end
J
Joshua Peek 已提交
242

243 244
  def test_delete_cookie_with_path
    get :delete_cookie_with_path
J
Jeremy Kemper 已提交
245
    assert_cookie_header "user_name=; path=/beaten; expires=Thu, 01-Jan-1970 00:00:00 GMT"
246
  end
J
Jeremy Kemper 已提交
247

248
  def test_cookies_persist_throughout_request
Y
Yehuda Katz 已提交
249 250
    response = get :authenticate
    assert response.headers["Set-Cookie"] =~ /user_name=david/
251
  end
252 253 254

  def test_permanent_cookie
    get :set_permanent_cookie
255 256
    assert_match(/Jamie/, @response.headers["Set-Cookie"])
    assert_match(%r(#{20.years.from_now.utc.year}), @response.headers["Set-Cookie"])
257
  end
J
Joshua Peek 已提交
258

259 260 261 262
  def test_signed_cookie
    get :set_signed_cookie
    assert_equal 45, @controller.send(:cookies).signed[:user_id]
  end
J
Joshua Peek 已提交
263

264 265 266 267 268
  def test_accessing_nonexistant_signed_cookie_should_not_raise_an_invalid_signature
    get :set_signed_cookie
    assert_nil @controller.send(:cookies).signed[:non_existant_attribute]
  end

269 270
  def test_permanent_signed_cookie
    get :set_permanent_signed_cookie
271
    assert_match(%r(#{20.years.from_now.utc.year}), @response.headers["Set-Cookie"])
272 273 274
    assert_equal 100, @controller.send(:cookies).signed[:remember_me]
  end

275 276 277 278 279
  def test_delete_and_set_cookie
    get :delete_and_set_cookie
    assert_cookie_header "user_name=david; path=/; expires=Mon, 10-Oct-2005 05:00:00 GMT"
    assert_equal({"user_name" => "david"}, @response.cookies)
  end
J
Joshua Peek 已提交
280

281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322
  def test_raise_data_overflow
    assert_raise(ActionDispatch::Cookies::CookieOverflow) do
      get :raise_data_overflow
    end
  end

  def test_tampered_cookies
    assert_nothing_raised do
      get :tampered_cookies
      assert_response :success
    end
  end

  def test_raises_argument_error_if_missing_secret
    assert_raise(ArgumentError, nil.inspect) {
      @request.env["action_dispatch.secret_token"] = nil
      get :set_signed_cookie
    }

    assert_raise(ArgumentError, ''.inspect) {
      @request.env["action_dispatch.secret_token"] = ""
      get :set_signed_cookie
    }
  end

  def test_raises_argument_error_if_secret_is_probably_insecure
    assert_raise(ArgumentError, "password".inspect) {
      @request.env["action_dispatch.secret_token"] = "password"
      get :set_signed_cookie
    }

    assert_raise(ArgumentError, "secret".inspect) {
      @request.env["action_dispatch.secret_token"] = "secret"
      get :set_signed_cookie
    }

    assert_raise(ArgumentError, "12345678901234567890123456789".inspect) {
      @request.env["action_dispatch.secret_token"] = "12345678901234567890123456789"
      get :set_signed_cookie
    }
  end

323 324 325 326 327 328
  def test_cookie_with_all_domain_option
    get :set_cookie_with_domain
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; domain=.nextangle.com; path=/"
  end

329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356
  def test_cookie_with_all_domain_option_using_a_non_standard_tld
    @request.host = "two.subdomains.nextangle.local"
    get :set_cookie_with_domain
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; domain=.nextangle.local; path=/"
  end

  def test_cookie_with_all_domain_option_using_australian_style_tld
    @request.host = "nextangle.com.au"
    get :set_cookie_with_domain
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; domain=.nextangle.com.au; path=/"
  end

  def test_cookie_with_all_domain_option_using_uk_style_tld
    @request.host = "nextangle.co.uk"
    get :set_cookie_with_domain
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; domain=.nextangle.co.uk; path=/"
  end

  def test_cookie_with_all_domain_option_using_host_with_port
    @request.host = "nextangle.local:3000"
    get :set_cookie_with_domain
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; domain=.nextangle.local; path=/"
  end

357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377
  def test_cookie_with_all_domain_option_using_localhost
    @request.host = "localhost"
    get :set_cookie_with_domain
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; path=/"
  end

  def test_cookie_with_all_domain_option_using_ipv4_address
    @request.host = "192.168.1.1"
    get :set_cookie_with_domain
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; path=/"
  end

  def test_cookie_with_all_domain_option_using_ipv6_address
    @request.host = "2001:0db8:85a3:0000:0000:8a2e:0370:7334"
    get :set_cookie_with_domain
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; path=/"
  end

378 379 380 381 382 383
  def test_deleting_cookie_with_all_domain_option
    get :delete_cookie_with_domain
    assert_response :success
    assert_cookie_header "user_name=; domain=.nextangle.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT"
  end

384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409
  def test_cookie_with_all_domain_option_and_tld_length
    get :set_cookie_with_domain_and_tld
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; domain=.nextangle.com; path=/"
  end

  def test_cookie_with_all_domain_option_using_a_non_standard_tld_and_tld_length
    @request.host = "two.subdomains.nextangle.local"
    get :set_cookie_with_domain_and_tld
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; domain=.nextangle.local; path=/"
  end

  def test_cookie_with_all_domain_option_using_host_with_port_and_tld_length
    @request.host = "nextangle.local:3000"
    get :set_cookie_with_domain_and_tld
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; domain=.nextangle.local; path=/"
  end

  def test_deleting_cookie_with_all_domain_option_and_tld_length
    get :delete_cookie_with_domain_and_tld
    assert_response :success
    assert_cookie_header "user_name=; domain=.nextangle.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT"
  end

410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444
  def test_cookie_with_several_preset_domains_using_one_of_these_domains
    @request.host = "example1.com"
    get :set_cookie_with_domains
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; domain=example1.com; path=/"
  end

  def test_cookie_with_several_preset_domains_using_other_domain
    @request.host = "other-domain.com"
    get :set_cookie_with_domains
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; path=/"
  end

  def test_cookie_with_several_preset_domains_using_shared_domain
    @request.host = "example3.com"
    get :set_cookie_with_domains
    assert_response :success
    assert_cookie_header "user_name=rizwanreza; domain=.example3.com; path=/"
  end

  def test_deletings_cookie_with_several_preset_domains_using_one_of_these_domains
    @request.host = "example2.com"
    get :delete_cookie_with_domains
    assert_response :success
    assert_cookie_header "user_name=; domain=example2.com; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT"
  end

  def test_deletings_cookie_with_several_preset_domains_using_other_domain
    @request.host = "other-domain.com"
    get :delete_cookie_with_domains
    assert_response :success
    assert_cookie_header "user_name=; path=/; expires=Thu, 01-Jan-1970 00:00:00 GMT"
  end

445

446
  def test_cookies_hash_is_indifferent_access
S
steve 已提交
447
      get :symbol_key
448 449
      assert_equal "david", cookies[:user_name]
      assert_equal "david", cookies['user_name']
S
steve 已提交
450 451 452
      get :string_key
      assert_equal "dhh", cookies[:user_name]
      assert_equal "dhh", cookies['user_name']
453 454
  end

S
steve 已提交
455 456


457
  def test_setting_request_cookies_is_indifferent_access
458 459
    cookies.clear
    cookies[:user_name] = "andrew"
460
    get :string_key_mock
461
    assert_equal "david", cookies['user_name']
462

463 464
    cookies.clear
    cookies['user_name'] = "andrew"
465
    get :symbol_key_mock
466
    assert_equal "david", cookies[:user_name]
467 468 469 470
  end

  def test_cookies_retained_across_requests
    get :symbol_key
471
    assert_cookie_header "user_name=david; path=/"
472 473 474 475 476 477 478 479 480 481 482 483 484 485 486
    assert_equal "david", cookies[:user_name]

    get :noop
    assert_nil @response.headers["Set-Cookie"]
    assert_equal "david", cookies[:user_name]

    get :noop
    assert_nil @response.headers["Set-Cookie"]
    assert_equal "david", cookies[:user_name]
  end

  def test_cookies_can_be_cleared
    get :symbol_key
    assert_equal "david", cookies[:user_name]

487
    cookies.clear
488 489 490 491 492 493 494
    get :noop
    assert_nil cookies[:user_name]

    get :symbol_key
    assert_equal "david", cookies[:user_name]
  end

495
  def test_can_set_http_cookie_header
496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543
    @request.env['HTTP_COOKIE'] = 'user_name=david'
    get :noop
    assert_equal 'david', cookies['user_name']
    assert_equal 'david', cookies[:user_name]

    get :noop
    assert_equal 'david', cookies['user_name']
    assert_equal 'david', cookies[:user_name]

    @request.env['HTTP_COOKIE'] = 'user_name=andrew'
    get :noop
    assert_equal 'andrew', cookies['user_name']
    assert_equal 'andrew', cookies[:user_name]
  end

  def test_can_set_request_cookies
    @request.cookies['user_name'] = 'david'
    get :noop
    assert_equal 'david', cookies['user_name']
    assert_equal 'david', cookies[:user_name]

    get :noop
    assert_equal 'david', cookies['user_name']
    assert_equal 'david', cookies[:user_name]

    @request.cookies[:user_name] = 'andrew'
    get :noop
    assert_equal 'andrew', cookies['user_name']
    assert_equal 'andrew', cookies[:user_name]
  end

  def test_cookies_precedence_over_http_cookie
    @request.env['HTTP_COOKIE'] = 'user_name=andrew'
    get :authenticate
    assert_equal 'david', cookies['user_name']
    assert_equal 'david', cookies[:user_name]

    get :noop
    assert_equal 'david', cookies['user_name']
    assert_equal 'david', cookies[:user_name]
  end

  def test_cookies_precedence_over_request_cookies
    @request.cookies['user_name'] = 'andrew'
    get :authenticate
    assert_equal 'david', cookies['user_name']
    assert_equal 'david', cookies[:user_name]

544
    get :noop
545 546
    assert_equal 'david', cookies['user_name']
    assert_equal 'david', cookies[:user_name]
547 548
  end

J
Jeremy Kemper 已提交
549 550 551 552
  private
    def assert_cookie_header(expected)
      header = @response.headers["Set-Cookie"]
      if header.respond_to?(:to_str)
553
        assert_equal expected.split("\n").sort, header.split("\n").sort
J
Jeremy Kemper 已提交
554 555 556 557
      else
        assert_equal expected.split("\n"), header
      end
    end
558 559 560 561 562 563 564 565 566

    def assert_not_cookie_header(expected)
      header = @response.headers["Set-Cookie"]
      if header.respond_to?(:to_str)
        assert_not_equal expected.split("\n").sort, header.split("\n").sort
      else
        assert_not_equal expected.split("\n"), header
      end
    end
567
end