oatpp-authkit/test
Uwe Schuster 0436139c87 extractToken: recognize the __Host-session cookie name (fix session regression)
`extractToken` only ever looked up `cookieValue(cookie, "session")`. After the
M-1 fix switched cookie parsing from substring to exact-name matching
(fafee12), a consumer that sets its session cookie under the hardened
`__Host-session` name (fewo-webapp, #535) stopped resolving — every browser
cookie request extracted an empty token and 401'd. The bare-`session`
substring used to incidentally match inside `__Host-session=`; exact matching
correctly no longer does.

Fix: add `sessionCookieToken(cookieHeader)` which tries the bare `session`
name and falls back to `__Host-session` (the `__Host-` prefix is strictly more
secure, so recognizing it is safe), and route `extractToken` through it. The
bare name is preferred when both are present. `cookieValue` keeps its exact
generic semantics unchanged. Backward-compatible: consumers using `session=`
are unaffected.

Tests: new `test_session_cookie_token` covering both names, precedence, and
substring traps. All 20 ctest targets pass.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-08-04 04:22:44 +02:00
..
CMakeLists.txt #16 (audit L-1..L-8): fix the low-severity findings 2026-05-29 14:03:01 +02:00
test_audit_log_repository.cpp #13: TemporalRepository save — stable-live + historical-copy semantics 2026-04-30 00:10:03 +02:00
test_body_size_limit.cpp #4: BodySizeLimitInterceptor — fail-closed on missing/malformed Content-Length 2026-04-25 21:36:50 +02:00
test_constant_time.cpp #16 (audit L-1..L-8): fix the low-severity findings 2026-05-29 14:03:01 +02:00
test_json_serialization.cpp #6: route ad-hoc JSON through ObjectMapper (Option A — DI everywhere, all-in-one) 2026-04-25 21:56:05 +02:00
test_negotiation.cpp #2: Browser-friendly 401/403 — content-negotiate JSON vs HTML/redirect 2026-04-25 13:23:08 +02:00
test_origin_check.cpp #16 (audit M-1..M-12): fix the medium-severity findings 2026-05-29 13:53:22 +02:00
test_queryable.cpp #16 (audit L-1..L-8): fix the low-severity findings 2026-05-29 14:03:01 +02:00
test_rate_limiter.cpp #16 (audit M-1..M-12): fix the medium-severity findings 2026-05-29 13:53:22 +02:00
test_redacted_field_repository.cpp #16 (audit M-1..M-12): fix the medium-severity findings 2026-05-29 13:53:22 +02:00
test_repository_decorators.cpp #16 (audit H-1..H-5): fix the five high-severity findings 2026-05-29 12:49:03 +02:00
test_repository_interface.cpp #10: TemporalFieldTraits<T> — decouple decorator from canonical column names 2026-04-29 14:23:40 +02:00
test_role_template_schema.cpp #14 PR 1: relocate role_templates module + Atlas migration docs 2026-05-06 12:36:18 +02:00
test_schema_contract.cpp #14 PR 0: replace imperative migration kit with declarative SchemaContract 2026-05-06 12:14:51 +02:00
test_security_headers.cpp #3: SecurityHeadersInterceptor — strict baseline + CspOverride ctor (Option B) 2026-04-25 21:54:58 +02:00
test_session_cookie.cpp #16 (audit M-1..M-12): fix the medium-severity findings 2026-05-29 13:53:22 +02:00
test_smtp_transport.cpp #16 (audit H-1..H-5): fix the five high-severity findings 2026-05-29 12:49:03 +02:00
test_temporal_field_traits.cpp #13: TemporalRepository save — stable-live + historical-copy semantics 2026-04-30 00:10:03 +02:00
test_token_extract.cpp extractToken: recognize the __Host-session cookie name (fix session regression) 2026-08-04 04:22:44 +02:00
test_user_permission_schema.cpp #14 PRs 2 & 3: relocate user_property_permissions + user_group_permissions 2026-05-06 12:39:52 +02:00
test_user_schema.cpp #14 PR 4: relocate users with temporal shape (Option B) 2026-05-06 12:57:59 +02:00