Add validation to ensure Cookie.Expiration is not set (#8967)
This commit is contained in:
parent
91dcbd44c1
commit
42b3fada31
|
|
@ -26,6 +26,7 @@ namespace Microsoft.Extensions.DependencyInjection
|
||||||
public static AuthenticationBuilder AddCookie(this AuthenticationBuilder builder, string authenticationScheme, string displayName, Action<CookieAuthenticationOptions> configureOptions)
|
public static AuthenticationBuilder AddCookie(this AuthenticationBuilder builder, string authenticationScheme, string displayName, Action<CookieAuthenticationOptions> configureOptions)
|
||||||
{
|
{
|
||||||
builder.Services.TryAddEnumerable(ServiceDescriptor.Singleton<IPostConfigureOptions<CookieAuthenticationOptions>, PostConfigureCookieAuthenticationOptions>());
|
builder.Services.TryAddEnumerable(ServiceDescriptor.Singleton<IPostConfigureOptions<CookieAuthenticationOptions>, PostConfigureCookieAuthenticationOptions>());
|
||||||
|
builder.Services.AddOptions<CookieAuthenticationOptions>(authenticationScheme).Validate(o => o.Cookie.Expiration == null, "Cookie.Expiration is ignored, use ExpireTimeSpan instead.");
|
||||||
return builder.AddScheme<CookieAuthenticationOptions, CookieAuthenticationHandler>(authenticationScheme, displayName, configureOptions);
|
return builder.AddScheme<CookieAuthenticationOptions, CookieAuthenticationHandler>(authenticationScheme, displayName, configureOptions);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -17,6 +17,7 @@ using Microsoft.AspNetCore.Http;
|
||||||
using Microsoft.AspNetCore.TestHost;
|
using Microsoft.AspNetCore.TestHost;
|
||||||
using Microsoft.AspNetCore.Testing.xunit;
|
using Microsoft.AspNetCore.Testing.xunit;
|
||||||
using Microsoft.Extensions.DependencyInjection;
|
using Microsoft.Extensions.DependencyInjection;
|
||||||
|
using Microsoft.Extensions.Options;
|
||||||
using Xunit;
|
using Xunit;
|
||||||
|
|
||||||
namespace Microsoft.AspNetCore.Authentication.Cookies
|
namespace Microsoft.AspNetCore.Authentication.Cookies
|
||||||
|
|
@ -140,20 +141,15 @@ namespace Microsoft.AspNetCore.Authentication.Cookies
|
||||||
}
|
}
|
||||||
|
|
||||||
[Fact]
|
[Fact]
|
||||||
public async Task CookieExpirationOptionIsIgnored()
|
public void SettingCookieExpirationOptionThrows()
|
||||||
{
|
{
|
||||||
var server = CreateServerWithServices(s => s.AddAuthentication().AddCookie(o =>
|
var services = new ServiceCollection();
|
||||||
|
services.AddAuthentication().AddCookie(o =>
|
||||||
{
|
{
|
||||||
o.Cookie.Name = "TestCookie";
|
|
||||||
// this is currently ignored. Users should set o.ExpireTimeSpan instead
|
|
||||||
o.Cookie.Expiration = TimeSpan.FromDays(10);
|
o.Cookie.Expiration = TimeSpan.FromDays(10);
|
||||||
}), SignInAsAlice);
|
});
|
||||||
|
var options = services.BuildServiceProvider().GetRequiredService<IOptionsMonitor<CookieAuthenticationOptions>>();
|
||||||
var transaction = await SendAsync(server, "http://example.com/testpath");
|
Assert.Throws<OptionsValidationException>(() => options.Get(CookieAuthenticationDefaults.AuthenticationScheme));
|
||||||
|
|
||||||
var setCookie = transaction.SetCookie;
|
|
||||||
Assert.StartsWith("TestCookie=", setCookie);
|
|
||||||
Assert.DoesNotContain("; expires=", setCookie);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
[Fact]
|
[Fact]
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue