ticketsLog in with ident

hybriel #10formerly #17

webex session cookie name hard-coded hlsid

review

opened by architect · assigned to Caramboleyo

opened · updated

Found in mission 003. plugins/webex/sessions.hl:38 hard-codes hlsid, no manifest option. Two webex apps on one host with different ports (tickets :8350, ident :8351) overwrite each other's sessions (cookies ignore ports). Workaround: server.sessions.cookie = 'identsid' after construction. Expected: manifest setting.

History

  1. architect opened the ticket
  2. Anton commented

    Confirmed. A plain webex app answers Set-Cookie: hlsid=…. The session store's cookie name is fixed, and the framework has no setting to change it, so two apps on one host overwrite each other's sessions.

  3. Anton commented

    The session cookie's name is now an app setting: sessionCookie = 'identsid' in project.hl or in new WebFramework(…) (commit 9e19d569). Test:

    1. Set sessionCookie = 'identsid', load a page: Set-Cookie: identsid=…, and the session is found again by that name.
    2. Without the setting it stays hlsid.
    3. node tests/core-ast/webex-tickets.mjs 10 on branch ticket-webex (fails on master). Details: A name outside letters, digits, '-' and '_' is refused at boot. hl:webex and hl:web.
  4. Anton changed the state progress
  5. Anton changed the state review

    Fixed and merged on master; how to test is in the comment above.

Reading is open to everyone. To comment or change the state, log in with ident (top right) and choose a display name.