批量优化功能
This commit is contained in:
@@ -399,12 +399,24 @@ func bearerTokenLogin(c *AuthLoginController) string {
|
||||
}
|
||||
|
||||
func setSessionCookieForCtx(ctx *context.Context, sid string) {
|
||||
// Secure 仅在 https 下添加:本地 http 联调时浏览器会丢弃 Secure Cookie,
|
||||
// 导致 authorize 识别不到会话又被送回登录页
|
||||
flag := cookieSecureFlag(ctx)
|
||||
ctx.Output.Header("Set-Cookie",
|
||||
fmt.Sprintf("%s=%s; Path=/; Max-Age=%d; HttpOnly; Secure; SameSite=Lax",
|
||||
sessionCookieName, sid, sessionCookieTTL))
|
||||
fmt.Sprintf("%s=%s; Path=/; Max-Age=%d; HttpOnly%s; SameSite=Lax",
|
||||
sessionCookieName, sid, sessionCookieTTL, flag))
|
||||
}
|
||||
|
||||
func clearSessionCookieForCtx(ctx *context.Context) {
|
||||
flag := cookieSecureFlag(ctx)
|
||||
ctx.Output.Header("Set-Cookie",
|
||||
fmt.Sprintf("%s=; Path=/; Max-Age=0; HttpOnly; Secure; SameSite=Lax", sessionCookieName))
|
||||
fmt.Sprintf("%s=; Path=/; Max-Age=0; HttpOnly%s; SameSite=Lax", sessionCookieName, flag))
|
||||
}
|
||||
|
||||
// cookieSecureFlag https 请求(或网关带 X-Forwarded-Proto: https)时返回 "; Secure"
|
||||
func cookieSecureFlag(ctx *context.Context) string {
|
||||
if ctx.Request.TLS != nil || strings.EqualFold(ctx.Request.Header.Get("X-Forwarded-Proto"), "https") {
|
||||
return "; Secure"
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user