Example #1
0
 def test_no_upgrade_oauth(self):
     # When g.domain == g.oauth_domain we might send a cookie even though
     # we're not using it for auth. Don't echo it back in responses.
     c.oauth_user = self._account
     self._setSessionCookie(days_old=60)
     upgrade_cookie_security()
     self.assertFalse(c.cookies[g.login_cookie].dirty)
Example #2
0
 def test_no_upgrade_oauth(self):
     # When g.domain == g.oauth_domain we might send a cookie even though
     # we're not using it for auth. Don't echo it back in responses.
     c.oauth_user = self._account
     self._setSessionCookie(days_old=60)
     upgrade_cookie_security()
     self.assertFalse(c.cookies[g.login_cookie].dirty)
Example #3
0
 def test_no_upgrade_loggedout(self):
     # We might have a now-invalid session cookie, don't bother upgrading
     # it if it's not acceptable.
     c.user_is_loggedin = False
     c.user = None
     self._setSessionCookie(days_old=60)
     upgrade_cookie_security()
     self.assertFalse(c.cookies[g.login_cookie].dirty)
Example #4
0
 def test_no_upgrade_loggedout(self):
     # We might have a now-invalid session cookie, don't bother upgrading
     # it if it's not acceptable.
     c.user_is_loggedin = False
     c.user = None
     self._setSessionCookie(days_old=60)
     upgrade_cookie_security()
     self.assertFalse(c.cookies[g.login_cookie].dirty)
Example #5
0
 def test_no_upgrade_no_cookie(self):
     # Don't send back a cookie if we didn't even use cookie auth
     upgrade_cookie_security()
     self.assertFalse(g.login_cookie in c.cookies)
Example #6
0
 def test_no_upgrade_http(self):
     c.secure = False
     self._setSessionCookie(days_old=60)
     upgrade_cookie_security()
     self.assertFalse(c.cookies[g.login_cookie].dirty)
Example #7
0
 def test_dont_remember_recent_session(self):
     self._setSessionCookie(days_old=5)
     upgrade_cookie_security()
     self.assertTrue(c.cookies[g.login_cookie].dirty)
     self.assertNotEqual(c.cookies[g.login_cookie].expires, NEVER)
Example #8
0
 def test_cookie_unchanged(self):
     self._setSessionCookie(days_old=60)
     old_session = c.cookies[g.login_cookie].value
     upgrade_cookie_security()
     self.assertTrue(c.cookies[g.login_cookie].dirty)
     self.assertEqual(old_session, c.cookies[g.login_cookie].value)
Example #9
0
 def test_upgrade_posts(self):
     self._setSessionCookie(days_old=60)
     upgrade_cookie_security()
     self.assertTrue(c.cookies[g.login_cookie].dirty)
     self.assertTrue(c.cookies[g.login_cookie].secure)
Example #10
0
 def test_cookie_unchanged(self):
     self._setSessionCookie(days_old=60)
     old_session = c.cookies[g.login_cookie].value
     upgrade_cookie_security()
     self.assertTrue(c.cookies[g.login_cookie].dirty)
     self.assertEqual(old_session, c.cookies[g.login_cookie].value)
Example #11
0
 def test_no_upgrade_secure_session(self):
     self._setSessionCookie(days_old=60)
     c.cookies["secure_session"] = Cookie(value="1")
     upgrade_cookie_security()
     self.assertFalse(c.cookies[g.login_cookie].dirty)
Example #12
0
 def test_no_upgrade_gets(self):
     request.method = "GET"
     self._setSessionCookie(days_old=60)
     upgrade_cookie_security()
     self.assertFalse(c.cookies[g.login_cookie].dirty)
Example #13
0
 def test_no_upgrade_no_cookie(self):
     # Don't send back a cookie if we didn't even use cookie auth
     upgrade_cookie_security()
     self.assertFalse(g.login_cookie in c.cookies)
Example #14
0
 def test_no_upgrade_http(self):
     c.secure = False
     self._setSessionCookie(days_old=60)
     upgrade_cookie_security()
     self.assertFalse(c.cookies[g.login_cookie].dirty)
Example #15
0
 def test_dont_remember_recent_session(self):
     self._setSessionCookie(days_old=5)
     upgrade_cookie_security()
     self.assertTrue(c.cookies[g.login_cookie].dirty)
     self.assertNotEqual(c.cookies[g.login_cookie].expires, NEVER)
Example #16
0
 def test_no_upgrade_secure_session(self):
     self._setSessionCookie(days_old=60)
     c.cookies["secure_session"] = Cookie(value="1")
     upgrade_cookie_security()
     self.assertFalse(c.cookies[g.login_cookie].dirty)
Example #17
0
 def test_no_upgrade_gets(self):
     request.method = "GET"
     self._setSessionCookie(days_old=60)
     upgrade_cookie_security()
     self.assertFalse(c.cookies[g.login_cookie].dirty)
Example #18
0
 def test_upgrade_posts(self):
     self._setSessionCookie(days_old=60)
     upgrade_cookie_security()
     self.assertTrue(c.cookies[g.login_cookie].dirty)
     self.assertTrue(c.cookies[g.login_cookie].secure)