From be9b2a7c7814847cc5b1abec68794631a8ce2f07 Mon Sep 17 00:00:00 2001 From: James Read Date: Sun, 20 Oct 2024 22:58:12 +0100 Subject: [PATCH] bugfix: Cookie expiry for OAuth2 & Local set to 1 year, not session (#451) --- internal/httpservers/restapi_auth_local.go | 7 +++++-- internal/httpservers/restapi_auth_oauth2.go | 2 +- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/internal/httpservers/restapi_auth_local.go b/internal/httpservers/restapi_auth_local.go index 8446687..b09fead 100644 --- a/internal/httpservers/restapi_auth_local.go +++ b/internal/httpservers/restapi_auth_local.go @@ -41,8 +41,11 @@ func forwardResponseHandlerLoginLocalUser(md metadata.MD, w http.ResponseWriter) http.SetCookie( w, &http.Cookie{ - Name: "olivetin-sid-local", - Value: sid, + Name: "olivetin-sid-local", + Value: sid, + MaxAge: 31556952, // 1 year + HttpOnly: true, + Path: "/", }, ) } diff --git a/internal/httpservers/restapi_auth_oauth2.go b/internal/httpservers/restapi_auth_oauth2.go index dae0852..9f890f8 100644 --- a/internal/httpservers/restapi_auth_oauth2.go +++ b/internal/httpservers/restapi_auth_oauth2.go @@ -96,7 +96,7 @@ func setOauthCallbackCookie(w http.ResponseWriter, r *http.Request, name, value cookie := &http.Cookie{ Name: name, Value: value, - MaxAge: int(time.Hour.Seconds()), + MaxAge: 31556952, // 1 year Secure: r.TLS != nil, HttpOnly: true, Path: "/",