mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-09-29 14:06:36 +08:00
b262880189
- Integrate CapWidget with dual-scope capability on the frontend and protect registration/send-email-code endpoints on the backend. - Set session cookie SameSite mode to Lax. - Propagate request context through auth source database operations and optimize username uniqueness validation. - Standardize local error naming to camelCase and resolve references. - Fix linter rules, missing SheetContent closing tag, and unit tests.
54 lines
1.4 KiB
Go
54 lines
1.4 KiB
Go
// Copyright 2025 linux.do
|
|
// Copyright 2026 Arctel.net
|
|
// SPDX-License-Identifier: Apache-2.0
|
|
|
|
package util
|
|
|
|
import (
|
|
"net/http"
|
|
"strings"
|
|
|
|
"github.com/Rain-kl/Wavelet/internal/config"
|
|
"github.com/gin-contrib/sessions"
|
|
)
|
|
|
|
// GetSessionOptions 根据配置构建 Session 选项
|
|
func GetSessionOptions(maxAge int) sessions.Options {
|
|
return sessions.Options{
|
|
Path: "/",
|
|
Domain: config.Config.App.SessionDomain,
|
|
MaxAge: maxAge,
|
|
HttpOnly: config.Config.App.SessionHTTPOnly,
|
|
Secure: config.Config.App.SessionSecure,
|
|
SameSite: http.SameSiteLaxMode,
|
|
}
|
|
}
|
|
|
|
// StripCookieMaxAgeAndExpires 从 Set-Cookie 响应头中移除 Max-Age 和 Expires,从而使其成为浏览器会话 Cookie
|
|
func StripCookieMaxAgeAndExpires(header http.Header, cookieName string) {
|
|
headers := header["Set-Cookie"]
|
|
if len(headers) == 0 {
|
|
return
|
|
}
|
|
|
|
newHeaders := make([]string, 0, len(headers))
|
|
for _, h := range headers {
|
|
if strings.HasPrefix(h, cookieName+"=") {
|
|
parts := strings.Split(h, ";")
|
|
newParts := make([]string, 0, len(parts))
|
|
for _, p := range parts {
|
|
trimmed := strings.TrimSpace(p)
|
|
lower := strings.ToLower(trimmed)
|
|
if strings.HasPrefix(lower, "max-age=") || strings.HasPrefix(lower, "expires=") {
|
|
continue
|
|
}
|
|
newParts = append(newParts, p)
|
|
}
|
|
newHeaders = append(newHeaders, strings.Join(newParts, ";"))
|
|
} else {
|
|
newHeaders = append(newHeaders, h)
|
|
}
|
|
}
|
|
header["Set-Cookie"] = newHeaders
|
|
}
|