Compare commits
No commits in common. "313dc401aea49684e658d2649c347b3b385da10d" and "4fff9c7702f5bc812dd15fa6de3fc293c4d599f0" have entirely different histories.
313dc401ae
...
4fff9c7702
@ -13,20 +13,14 @@
|
|||||||
que quien use este ordenador después podría volver a entrar sin escribirla.
|
que quien use este ordenador después podría volver a entrar sin escribirla.
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
{# There was a "Cerrar sesión del todo" button here that linked straight to
|
|
||||||
/user/logout. It never worked: that route is POST-only, so the click was
|
|
||||||
a GET and the account server answered 404 with the session untouched.
|
|
||||||
It cannot be made to work from here either — signing out needs a CSRF
|
|
||||||
token belonging to that other domain, which this page has no way to read,
|
|
||||||
and that restriction is the whole point of the check. So the page gives
|
|
||||||
the instruction instead of pretending to do it. #}
|
|
||||||
<p>
|
<p>
|
||||||
<a class="btn" href="{{ gitea_url }}">Ir al servidor de cuentas</a>
|
<a class="btn" href="{{ gitea_url }}/user/logout">Cerrar sesión del todo</a>
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<p class="muted small">
|
<p class="muted small">
|
||||||
Allí, abre el menú de tu perfil (arriba a la derecha) y elige
|
Si esa página no te desconecta, abre el menú de tu perfil
|
||||||
<em>Cerrar sesión</em>. Cerrar el navegador del todo también sirve.
|
<a href="{{ gitea_url }}">ahí</a> y elige <em>Sign Out</em>.
|
||||||
|
Cerrar el navegador también sirve.
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<p class="muted small">
|
<p class="muted small">
|
||||||
|
|||||||
@ -124,12 +124,7 @@ def test_logout_says_the_gitea_session_is_still_open(client, db, make_member, si
|
|||||||
|
|
||||||
assert response.status_code == 200
|
assert response.status_code == 200
|
||||||
assert "sigue conectado" in page # the warning, not a redirect
|
assert "sigue conectado" in page # the warning, not a redirect
|
||||||
# This line used to assert `/user/logout` was in the page, which made the
|
assert "/user/logout" in page
|
||||||
# suite enforce the bug rather than catch it: that route is POST-only, so
|
|
||||||
# the link it was guarding answered 404 and closed nothing. What the page
|
|
||||||
# owes the member is the instruction and a way to get there.
|
|
||||||
assert "/user/logout" not in page
|
|
||||||
assert "Cerrar sesión" in page
|
|
||||||
|
|
||||||
with client.session_transaction() as session:
|
with client.session_transaction() as session:
|
||||||
assert "member_id" not in session
|
assert "member_id" not in session
|
||||||
|
|||||||
@ -38,22 +38,6 @@ def test_every_post_form_carries_a_csrf_token(template):
|
|||||||
assert "csrf_token" in form, f"{template.name} has a POST form without a CSRF token"
|
assert "csrf_token" in form, f"{template.name} has a POST form without a CSRF token"
|
||||||
|
|
||||||
|
|
||||||
@pytest.mark.parametrize("template", TEMPLATES, ids=lambda p: p.name)
|
|
||||||
def test_nothing_links_to_the_account_server_logout(template):
|
|
||||||
"""A link there is a GET, and that route is POST-only, so the browser gets
|
|
||||||
a 404 and the session it was meant to end carries on. We shipped exactly
|
|
||||||
that and it went unnoticed for a week, because a dead link on a page nobody
|
|
||||||
reaches twice looks like nothing at all.
|
|
||||||
|
|
||||||
It cannot be fixed by turning the link into a form either: the POST needs a
|
|
||||||
CSRF token belonging to that other domain, which is unreadable from here by
|
|
||||||
design. The page has to tell the member what to do instead."""
|
|
||||||
html = JINJA_COMMENT.sub("", template.read_text(encoding="utf-8"))
|
|
||||||
assert "/user/logout" not in html, (
|
|
||||||
f"{template.name} links to /user/logout, which answers 404 to a GET"
|
|
||||||
)
|
|
||||||
|
|
||||||
|
|
||||||
# --- the name of the software behind the login ---------------------------
|
# --- the name of the software behind the login ---------------------------
|
||||||
#
|
#
|
||||||
# Members sign in through an OAuth provider that happens to be Gitea. They are
|
# Members sign in through an OAuth provider that happens to be Gitea. They are
|
||||||
|
|||||||
@ -734,21 +734,10 @@ Gitea's CSRF token. The `prompt=login` parameter that would force
|
|||||||
re-authentication is undocumented in every released version of Gitea's OAuth2
|
re-authentication is undocumented in every released version of Gitea's OAuth2
|
||||||
provider, and a security control should not rest on that.
|
provider, and a security control should not rest on that.
|
||||||
|
|
||||||
So the logout page says plainly what is and is not closed, and then **tells the
|
So the logout page says plainly what is and is not closed, and offers the link
|
||||||
member how to finish the job**: go to the account server, open the profile menu,
|
that finishes the job. On a shared computer, use it — or close the browser,
|
||||||
choose *Cerrar sesión*. Or close the browser, which also works — the
|
which also works. The members-area cookie is already a browser-session cookie,
|
||||||
members-area cookie is a browser-session cookie and does not survive that.
|
so it does not survive that either way.
|
||||||
|
|
||||||
That wording is deliberate, and this paragraph used to say something else. The
|
|
||||||
page shipped with a *"Cerrar sesión del todo"* button linking straight to
|
|
||||||
`/user/logout`, which contradicted the paragraph directly above it: a click is
|
|
||||||
a GET, the route is POST-only, and the server answered **404** with the session
|
|
||||||
untouched. The button was live for a week. Nobody noticed, because a dead link
|
|
||||||
on a page you reach once looks like nothing at all — and because it was never
|
|
||||||
clicked against a running Gitea before shipping.
|
|
||||||
|
|
||||||
`apps/board/tests/test_templates.py` now fails the build if any template links
|
|
||||||
to `/user/logout` again.
|
|
||||||
|
|
||||||
## 13. Email: invitations and passwords
|
## 13. Email: invitations and passwords
|
||||||
|
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user