Encrypt cookies
This commit is contained in:
@@ -37,6 +37,10 @@ type Server struct {
|
||||
// none. Resolved once: the assets cannot change while the process runs.
|
||||
favicon string
|
||||
|
||||
// sessions seals the login cookie, so the token it remembers is not
|
||||
// legible to anyone reading the browser's cookie jar.
|
||||
sessions *sealer
|
||||
|
||||
now func() time.Time // swappable in tests
|
||||
}
|
||||
|
||||
@@ -45,6 +49,10 @@ func New(cfg *config.Config, st *store.Store, tokens *auth.File, log *slog.Logge
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
sessions, err := newSealer(sessionKeyPath(cfg.DataDir))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
s := &Server{
|
||||
cfg: cfg,
|
||||
store: st,
|
||||
@@ -56,6 +64,7 @@ func New(cfg *config.Config, st *store.Store, tokens *auth.File, log *slog.Logge
|
||||
slots: make(chan struct{}, cfg.MaxConcurrent),
|
||||
now: time.Now,
|
||||
favicon: faviconFor(web.Static()),
|
||||
sessions: sessions,
|
||||
}
|
||||
s.handler = s.routes()
|
||||
return s, nil
|
||||
@@ -245,7 +254,7 @@ func (s *Server) page(r *http.Request, title string, script bool) page {
|
||||
if s.favicon != "" {
|
||||
p.Favicon = s.cfg.BasePath + "static/" + s.favicon
|
||||
}
|
||||
if lim, err := s.limitsFor(r, cookieCredential(r)); err == nil {
|
||||
if lim, err := s.limitsFor(r, s.cookieCredential(r)); err == nil {
|
||||
p.User, p.Admin = lim.Name, lim.Admin
|
||||
}
|
||||
return p
|
||||
|
||||
Reference in New Issue
Block a user