Recognize semi-colon separated cookies too (#2078)

This fixes a bug where the frontend UI sends GRPC cookies via a single semi-colon
separated string, which our new token parsing algorithm did not recognize as valid.
Now we account for that special case, at the small expense of greater overall
computational complexity.
This commit is contained in:
reesporte 2022-05-24 21:45:33 -05:00 • committed by GitHub
parent ba44bc86f6
commit d9b13eebc8
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
2 changed files with 22 additions and 8 deletions

View file

@ -1730,14 +1730,17 @@ func getTokensFromMetadata(md metadata.MD) (string, string) {
if !ok || !ok2 {
if cookies, there := md["cookie"]; there {
for _, cookie := range cookies {
if strings.HasPrefix(cookie, authn.AccessCookieName+"=") && len(access) == 0 {
access = strings.Split(cookie, authn.AccessCookieName+"=")[1:]
} else if strings.HasPrefix(cookie, authn.RefreshCookieName+"=") && len(refresh) == 0 {
refresh = strings.Split(cookie, authn.RefreshCookieName+"=")[1:]
}
if len(access) > 0 && len(refresh) > 0 {
break
for _, c := range cookies {
for _, cookie := range strings.Split(c, ";") {
cookie = strings.TrimSpace(cookie)
if strings.HasPrefix(cookie, authn.AccessCookieName+"=") && len(access) == 0 {
access = strings.Split(cookie, authn.AccessCookieName+"=")[1:]
} else if strings.HasPrefix(cookie, authn.RefreshCookieName+"=") && len(refresh) == 0 {
refresh = strings.Split(cookie, authn.RefreshCookieName+"=")[1:]
}
if len(access) > 0 && len(refresh) > 0 {
break
}
}
}
}

View file

@ -2,6 +2,7 @@ package server
import (
"context"
"fmt"
"strings"
"testing"
@ -46,6 +47,16 @@ func TestGetTokensFromMetadata(t *testing.T) {
},
},
},
"semiColonCookies": {
access: "something",
refresh: "somethingElse",
setCookie: false,
md: metadata.MD{
"cookie": []string{
fmt.Sprintf("%s=something; %s=somethingElse", authn.AccessCookieName, authn.RefreshCookieName),
},
},
},
"inTheHeaderNoRefresh": {
access: "something",
refresh: "",