MockCookie compares attributes in case-insensitive manner

Closes gh-22786
This commit is contained in:
Juergen Hoeller 2019-04-12 11:10:02 +02:00
parent 49557471a9
commit b07d46da99
3 changed files with 40 additions and 23 deletions

View File

@ -1,5 +1,5 @@
/* /*
* Copyright 2002-2018 the original author or authors. * Copyright 2002-2019 the original author or authors.
* *
* Licensed under the Apache License, Version 2.0 (the "License"); * Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License. * you may not use this file except in compliance with the License.
@ -20,12 +20,14 @@ import javax.servlet.http.Cookie;
import org.springframework.lang.Nullable; import org.springframework.lang.Nullable;
import org.springframework.util.Assert; import org.springframework.util.Assert;
import org.springframework.util.StringUtils;
/** /**
* Extension of {@code Cookie} with extra attributes, as defined in * Extension of {@code Cookie} with extra attributes, as defined in
* <a href="https://tools.ietf.org/html/rfc6265">RFC 6265</a>. * <a href="https://tools.ietf.org/html/rfc6265">RFC 6265</a>.
* *
* @author Vedran Pavic * @author Vedran Pavic
* @author Juergen Hoeller
* @since 5.1 * @since 5.1
*/ */
public class MockCookie extends Cookie { public class MockCookie extends Cookie {
@ -86,22 +88,22 @@ public class MockCookie extends Cookie {
MockCookie cookie = new MockCookie(name, value); MockCookie cookie = new MockCookie(name, value);
for (String attribute : attributes) { for (String attribute : attributes) {
if (attribute.startsWith("Domain")) { if (StringUtils.startsWithIgnoreCase(attribute, "Domain")) {
cookie.setDomain(extractAttributeValue(attribute, setCookieHeader)); cookie.setDomain(extractAttributeValue(attribute, setCookieHeader));
} }
else if (attribute.startsWith("Max-Age")) { else if (StringUtils.startsWithIgnoreCase(attribute, "Max-Age")) {
cookie.setMaxAge(Integer.parseInt(extractAttributeValue(attribute, setCookieHeader))); cookie.setMaxAge(Integer.parseInt(extractAttributeValue(attribute, setCookieHeader)));
} }
else if (attribute.startsWith("Path")) { else if (StringUtils.startsWithIgnoreCase(attribute, "Path")) {
cookie.setPath(extractAttributeValue(attribute, setCookieHeader)); cookie.setPath(extractAttributeValue(attribute, setCookieHeader));
} }
else if (attribute.startsWith("Secure")) { else if (StringUtils.startsWithIgnoreCase(attribute, "Secure")) {
cookie.setSecure(true); cookie.setSecure(true);
} }
else if (attribute.startsWith("HttpOnly")) { else if (StringUtils.startsWithIgnoreCase(attribute, "HttpOnly")) {
cookie.setHttpOnly(true); cookie.setHttpOnly(true);
} }
else if (attribute.startsWith("SameSite")) { else if (StringUtils.startsWithIgnoreCase(attribute, "SameSite")) {
cookie.setSameSite(extractAttributeValue(attribute, setCookieHeader)); cookie.setSameSite(extractAttributeValue(attribute, setCookieHeader));
} }
} }

View File

@ -1,5 +1,5 @@
/* /*
* Copyright 2002-2018 the original author or authors. * Copyright 2002-2019 the original author or authors.
* *
* Licensed under the Apache License, Version 2.0 (the "License"); * Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License. * you may not use this file except in compliance with the License.
@ -34,6 +34,7 @@ public class MockCookieTests {
@Rule @Rule
public final ExpectedException exception = ExpectedException.none(); public final ExpectedException exception = ExpectedException.none();
@Test @Test
public void constructCookie() { public void constructCookie() {
MockCookie cookie = new MockCookie("SESSION", "123"); MockCookie cookie = new MockCookie("SESSION", "123");
@ -57,9 +58,7 @@ public class MockCookieTests {
@Test @Test
public void parseHeaderWithoutAttributes() { public void parseHeaderWithoutAttributes() {
MockCookie cookie; MockCookie cookie = MockCookie.parse("SESSION=123");
cookie = MockCookie.parse("SESSION=123");
assertCookie(cookie, "SESSION", "123"); assertCookie(cookie, "SESSION", "123");
cookie = MockCookie.parse("SESSION=123;"); cookie = MockCookie.parse("SESSION=123;");
@ -80,6 +79,11 @@ public class MockCookieTests {
assertEquals("Lax", cookie.getSameSite()); assertEquals("Lax", cookie.getSameSite());
} }
private void assertCookie(MockCookie cookie, String name, String value) {
assertEquals(name, cookie.getName());
assertEquals(value, cookie.getValue());
}
@Test @Test
public void parseNullHeader() { public void parseNullHeader() {
exception.expect(IllegalArgumentException.class); exception.expect(IllegalArgumentException.class);
@ -103,9 +107,18 @@ public class MockCookieTests {
MockCookie.parse(header); MockCookie.parse(header);
} }
private void assertCookie(MockCookie cookie, String name, String value) { @Test
assertEquals(name, cookie.getName()); public void parseHeaderWithAttributesCaseSensitivity() {
assertEquals(value, cookie.getValue()); MockCookie cookie = MockCookie.parse(
"SESSION=123; domain=example.com; max-age=60; path=/; secure; httponly; samesite=Lax");
assertCookie(cookie, "SESSION", "123");
assertEquals("example.com", cookie.getDomain());
assertEquals(60, cookie.getMaxAge());
assertEquals("/", cookie.getPath());
assertTrue(cookie.getSecure());
assertTrue(cookie.isHttpOnly());
assertEquals("Lax", cookie.getSameSite());
} }
} }

View File

@ -1,5 +1,5 @@
/* /*
* Copyright 2002-2018 the original author or authors. * Copyright 2002-2019 the original author or authors.
* *
* Licensed under the Apache License, Version 2.0 (the "License"); * Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License. * you may not use this file except in compliance with the License.
@ -20,12 +20,14 @@ import javax.servlet.http.Cookie;
import org.springframework.lang.Nullable; import org.springframework.lang.Nullable;
import org.springframework.util.Assert; import org.springframework.util.Assert;
import org.springframework.util.StringUtils;
/** /**
* Extension of {@code Cookie} with extra attributes, as defined in * Extension of {@code Cookie} with extra attributes, as defined in
* <a href="https://tools.ietf.org/html/rfc6265">RFC 6265</a>. * <a href="https://tools.ietf.org/html/rfc6265">RFC 6265</a>.
* *
* @author Vedran Pavic * @author Vedran Pavic
* @author Juergen Hoeller
* @since 5.1 * @since 5.1
*/ */
public class MockCookie extends Cookie { public class MockCookie extends Cookie {
@ -86,22 +88,22 @@ public class MockCookie extends Cookie {
MockCookie cookie = new MockCookie(name, value); MockCookie cookie = new MockCookie(name, value);
for (String attribute : attributes) { for (String attribute : attributes) {
if (attribute.startsWith("Domain")) { if (StringUtils.startsWithIgnoreCase(attribute, "Domain")) {
cookie.setDomain(extractAttributeValue(attribute, setCookieHeader)); cookie.setDomain(extractAttributeValue(attribute, setCookieHeader));
} }
else if (attribute.startsWith("Max-Age")) { else if (StringUtils.startsWithIgnoreCase(attribute, "Max-Age")) {
cookie.setMaxAge(Integer.parseInt(extractAttributeValue(attribute, setCookieHeader))); cookie.setMaxAge(Integer.parseInt(extractAttributeValue(attribute, setCookieHeader)));
} }
else if (attribute.startsWith("Path")) { else if (StringUtils.startsWithIgnoreCase(attribute, "Path")) {
cookie.setPath(extractAttributeValue(attribute, setCookieHeader)); cookie.setPath(extractAttributeValue(attribute, setCookieHeader));
} }
else if (attribute.startsWith("Secure")) { else if (StringUtils.startsWithIgnoreCase(attribute, "Secure")) {
cookie.setSecure(true); cookie.setSecure(true);
} }
else if (attribute.startsWith("HttpOnly")) { else if (StringUtils.startsWithIgnoreCase(attribute, "HttpOnly")) {
cookie.setHttpOnly(true); cookie.setHttpOnly(true);
} }
else if (attribute.startsWith("SameSite")) { else if (StringUtils.startsWithIgnoreCase(attribute, "SameSite")) {
cookie.setSameSite(extractAttributeValue(attribute, setCookieHeader)); cookie.setSameSite(extractAttributeValue(attribute, setCookieHeader));
} }
} }