Compare commits

...

1 Commits

Author SHA1 Message Date
kennethreitz 4d15dbc465 fix for sessions 2018-10-27 07:10:05 -04:00
3 changed files with 26 additions and 2 deletions
+5 -2
View File
@@ -2,6 +2,7 @@ import json
import os
from pathlib import Path
from base64 import b64encode
import apistar
import itsdangerous
@@ -242,7 +243,7 @@ class API:
def _prepare_cookies(self, resp):
if resp.cookies:
header = " ".join([f"{k}={v}" for k, v in resp.cookies.items()])
header = " ".join([f"{k}={v};" for k, v in resp.cookies.items()])
resp.headers["Set-Cookie"] = header
@property
@@ -252,7 +253,9 @@ class API:
def _prepare_session(self, resp):
if resp.session:
data = self._signer.sign(json.dumps(resp.session).encode("utf-8"))
data = self._signer.sign(
b64encode(json.dumps(resp.session).encode("utf-8"))
)
resp.cookies[self.session_cookie] = data.decode("utf-8")
@staticmethod
+4
View File
@@ -1,6 +1,7 @@
import io
import json
import gzip
from base64 import b64decode
from http.cookies import SimpleCookie
@@ -109,8 +110,11 @@ class Request:
def session(self):
"""The session data, in dict form, from the Request."""
if "Responder-Session" in self.cookies:
data = self.cookies[self.api.session_cookie]
data = self.api._signer.unsign(data)
data = b64decode(data)
return json.loads(data)
return {}
+17
View File
@@ -528,3 +528,20 @@ def test_redirects(api, session):
resp.text = "redirected"
assert session.get("/1").url == "http://testserver/1"
def test_session_thoroughly(api, session):
@api.route("/set")
def set(req, resp):
resp.session["hello"] = "world"
api.redirect(resp, location="/get")
@api.route("/get")
def get(req, resp):
resp.media = {"session": req.session}
r = session.get(api.url_for(set))
print(r.headers)
r = session.get(api.url_for(get))
print(r.request.headers)
assert r.json() == {"session": {"hello": "world"}}