Skip to content
This repository was archived by the owner on Jun 23, 2023. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 18 additions & 28 deletions docs/source/contents/conf.rst
Original file line number Diff line number Diff line change
Expand Up @@ -150,42 +150,32 @@ An example::
check_session_iframe: https://127.0.0.1:5000/check_session_iframe


-----------
cookie_name
-----------

An example::

"cookie_name": {
"session": "oidc_op",
"register": "oidc_op_rp",
"session_management": "sman"
},

-------------
cookie_dealer
cookie_handler
-------------

An example::

"cookie_dealer": {
"class": "oidcop.cookie.CookieDealer",
"cookie_handler": {
"class": "oidcop.cookie_handler.CookieHandler",
"kwargs": {
"sign_jwk": {
"filename": "private/cookie_sign_jwk.json",
"type": "OCT",
"kid": "cookie_sign_key_id"
"keys": {
"private_path": f"{OIDC_JWKS_PRIVATE_PATH}/cookie_jwks.json",
"key_defs": [
{"type": "OCT", "use": ["enc"], "kid": "enc"},
{"type": "OCT", "use": ["sig"], "kid": "sig"}
],
"read_only": False
},
"enc_jwk": {
"filename": "private/cookie_enc_jwk.json",
"type": "OCT",
"kid": "cookie_enc_key_id"
"flags": {
"samesite": "None",
"httponly": True,
"secure": True,
},
"default_values": {
"name": "oidc_op",
"domain": "127.0.0.1",
"path": "/",
"max_age": 3600
"name": {
"session": "oidc_op",
"register": "oidc_op_rp",
"session_management": "sman"
}
}
},
Expand Down
7 changes: 3 additions & 4 deletions example/flask_op/views.py
Original file line number Diff line number Diff line change
Expand Up @@ -28,10 +28,9 @@


def _add_cookie(resp, cookie_spec):
kwargs = {'value': cookie_spec["value"]}
for param in ['expires', 'max-age']:
if param in cookie_spec:
kwargs[param] = cookie_spec[param]
kwargs = {k:v
for k,v in cookie_spec.items()
if k not in ('name',)}
kwargs["path"] = "/"
resp.set_cookie(cookie_spec["name"], **kwargs)

Expand Down
17 changes: 15 additions & 2 deletions src/oidcop/cookie_handler.py
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ def __init__(
keys: Optional[dict] = None,
sign_alg: [str] = "SHA256",
name: Optional[dict] = None,
**kwargs
):

if keys:
Expand Down Expand Up @@ -77,6 +78,15 @@ def __init__(
else:
self.name = name

self.flags = kwargs.get(
'flags',
{
"samesite": "None",
"httponly": True,
"secure": True,
}
)

def _sign_enc_payload(self, payload: str, timestamp: Optional[Union[int, str]] = 0):
"""
Creates signed and/or encrypted information.
Expand Down Expand Up @@ -211,9 +221,12 @@ def make_cookie_content(
content = {"name": name, "value": _cookie_value}

if max_age == -1:
content["Expires"] = "Thu, 01 Jan 1970 00:00:00 GMT;"
content["expires"] = "Thu, 01 Jan 1970 00:00:00 GMT;"
elif max_age:
content["Max-Age"] = epoch_in_a_while(seconds=max_age)
content["max-age"] = epoch_in_a_while(seconds=max_age)

for k,v in self.flags.items():
content[k] = v

return content

Expand Down
3 changes: 2 additions & 1 deletion src/oidcop/endpoint_context.py
Original file line number Diff line number Diff line change
Expand Up @@ -232,9 +232,10 @@ def __init__(
self.claims_interface = None

def new_cookie(self, name: str, max_age: Optional[int] = 0, **kwargs):
return self.cookie_handler.make_cookie_content(
cookie_cont = self.cookie_handler.make_cookie_content(
name=name, value=json.dumps(kwargs), max_age=max_age
)
return cookie_cont

def set_scopes_handler(self):
_spec = self.conf.get("scopes_handler")
Expand Down
32 changes: 24 additions & 8 deletions tests/test_09_cookie_handler.py
Original file line number Diff line number Diff line change
Expand Up @@ -25,15 +25,19 @@ def test_init(self):
def test_make_cookie_content(self):
_cookie_info = self.cookie_handler.make_cookie_content("oidcop", "value", "sso")
assert _cookie_info
assert set(_cookie_info.keys()) == {"name", "value"}
assert set(_cookie_info.keys()) == {
"name", "value", "samesite", "httponly", "secure"
}
assert len(_cookie_info["value"].split("|")) == 3

def test_make_cookie_content_max_age(self):
_cookie_info = self.cookie_handler.make_cookie_content(
"oidcop", "value", "sso", max_age=3600
)
assert _cookie_info
assert set(_cookie_info.keys()) == {"name", "value", "Max-Age"}
assert set(_cookie_info.keys()) == {
'name', 'value', 'max-age', 'samesite', 'httponly', 'secure'
}
assert len(_cookie_info["value"].split("|")) == 3

def test_read_cookie_info(self):
Expand Down Expand Up @@ -72,15 +76,19 @@ def make_cookie_handler(self):
def test_make_cookie_content(self):
_cookie_info = self.cookie_handler.make_cookie_content("oidcop", "value", "sso")
assert _cookie_info
assert set(_cookie_info.keys()) == {"name", "value"}
assert set(_cookie_info.keys()) == {
'name', 'value', 'samesite', 'httponly', 'secure'
}
assert len(_cookie_info["value"].split("|")) == 4

def test_make_cookie_content_max_age(self):
_cookie_info = self.cookie_handler.make_cookie_content(
"oidcop", "value", "sso", max_age=3600
)
assert _cookie_info
assert set(_cookie_info.keys()) == {"name", "value", "Max-Age"}
assert set(_cookie_info.keys()) == {
'name', 'value', 'max-age', 'samesite', 'httponly', 'secure'
}
assert len(_cookie_info["value"].split("|")) == 4

def test_read_cookie_info(self):
Expand Down Expand Up @@ -118,15 +126,19 @@ def make_cookie_content_handler(self):
def test_make_cookie_content(self):
_cookie_info = self.cookie_handler.make_cookie_content("oidcop", "value", "sso")
assert _cookie_info
assert set(_cookie_info.keys()) == {"name", "value"}
assert set(_cookie_info.keys()) == {
'name', 'value', 'samesite', 'httponly', 'secure'
}
assert len(_cookie_info["value"].split("|")) == 4

def test_make_cookie_content_max_age(self):
_cookie_info = self.cookie_handler.make_cookie_content(
"oidcop", "value", "sso", max_age=3600
)
assert _cookie_info
assert set(_cookie_info.keys()) == {"name", "value", "Max-Age"}
assert set(_cookie_info.keys()) == {
'name', 'value', 'max-age', 'samesite', 'httponly', 'secure'
}
assert len(_cookie_info["value"].split("|")) == 4

def test_read_cookie_info(self):
Expand Down Expand Up @@ -168,15 +180,19 @@ def make_cookie_handler(self):
def test_make_cookie_content(self):
_cookie_info = self.cookie_handler.make_cookie_content("oidcop", "value", "sso")
assert _cookie_info
assert set(_cookie_info.keys()) == {"name", "value"}
assert set(_cookie_info.keys()) == {
'name', 'value', 'samesite', 'httponly', 'secure'
}
assert len(_cookie_info["value"].split("|")) == 4

def test_make_cookie_content_max_age(self):
_cookie_info = self.cookie_handler.make_cookie_content(
"oidcop", "value", "sso", max_age=3600
)
assert _cookie_info
assert set(_cookie_info.keys()) == {"name", "value", "Max-Age"}
assert set(_cookie_info.keys()) == {
'name', 'value', 'max-age', 'samesite', 'httponly', 'secure'
}
assert len(_cookie_info["value"].split("|")) == 4

def test_read_cookie_info(self):
Expand Down
2 changes: 1 addition & 1 deletion tests/test_30_oidc_end_session.py
Original file line number Diff line number Diff line change
Expand Up @@ -605,7 +605,7 @@ def test_kill_cookies(self):
assert set(_names) == {"oidc_op_sman", "oidc_op"}
_values = [ci["value"] for ci in _info]
assert set(_values) == {"", ""}
_exps = [ci["Expires"] for ci in _info]
_exps = [ci["expires"] for ci in _info]
assert set(_exps) == {
"Thu, 01 Jan 1970 00:00:00 GMT;",
"Thu, 01 Jan 1970 00:00:00 GMT;",
Expand Down