fix(panel): mark the webview acknowledgement cookie secure

This commit is contained in:
flyemoji committed 2026-09-29 14:08:23 +09:00
1 parent 118e3bc0c4
commit c0ee75efe4
2 files changed
+3 -2

No files matched your search

+1
View File
@@ -75,6 +75,7 @@ func guardInAppWebView(w http.ResponseWriter, r *http.Request) bool {
Value: "1", Value: "1",
Path: "/", Path: "/",
HttpOnly: true, HttpOnly: true,
Secure: true,
SameSite: http.SameSiteLaxMode, SameSite: http.SameSiteLaxMode,
MaxAge: 3600, MaxAge: 3600,
}) })
+2 -2
View File
@@ -138,12 +138,12 @@ func TestGuardHonorsAcknowledgement(t *testing.T) {
} }
var acked bool var acked bool
for _, c := range w.Result().Cookies() { for _, c := range w.Result().Cookies() {
if c.Name == webViewAckCookie && c.Value == "1" { if c.Name == webViewAckCookie && c.Value == "1" && c.Secure {
acked = true acked = true
} }
} }
if !acked { if !acked {
t.Fatalf("ua_ack did not set the ack cookie") t.Fatalf("ua_ack did not set a Secure ack cookie")
} }
// A subsequent navigation carrying the ack cookie is not interrupted. // A subsequent navigation carrying the ack cookie is not interrupted.