Commit 81f22700 authored by Graham Leggett's avatar Graham Leggett
Browse files

mod_session_cookie, mod_session_dbd: Make sure cookies are set both

within the output headers and error output headers, so that the
session is maintained across redirects.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@690501 13f79535-47bb-0310-9956-ffa450edef68
parent 2ab9bc65
Loading
Loading
Loading
Loading
+4 −0
Changes for CHANGES: 4 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -2,6 +2,10 @@
Changes with Apache 2.3.0
[ When backported to 2.2.x, remove entry from this file ]

  *) mod_session_cookie, mod_session_dbd: Make sure cookies are set both
     within the output headers and error output headers, so that the
     session is maintained across redirects. [Graham Leggett]

  *) mod_auth_form: Make sure the logged in user is populated correctly
     after a form login. Fixes a missing REMOTE_USER variable directly
     following a login. [Graham Leggett]
+2 −1
Changes for include/ap_mmn.h: 2 added lines, 1 removed line.
Original line number Diff line number Diff line
@@ -167,13 +167,14 @@
 *                         proxy_worker struct.
 * 20080722.2 (2.3.0-dev)  Add scolonsep to proxy_balancer
 * 20080829.0 (2.3.0-dev)  Add cookie attributes when removing cookies
 * 20080830.0 (2.3.0-dev)  Cookies can be set on headers_out and err_headers_out
 *
 */

#define MODULE_MAGIC_COOKIE 0x41503234UL /* "AP24" */

#ifndef MODULE_MAGIC_NUMBER_MAJOR
#define MODULE_MAGIC_NUMBER_MAJOR 20080829
#define MODULE_MAGIC_NUMBER_MAJOR 20080830
#endif
#define MODULE_MAGIC_NUMBER_MINOR 0                     /* 0...n */

+13 −5
Changes for include/util_cookies.h: 13 added lines, 5 removed lines.
Original line number Diff line number Diff line
@@ -41,7 +41,7 @@ extern "C" {
#define SET_COOKIE "Set-Cookie"
#define SET_COOKIE2 "Set-Cookie2"
#define DEFAULT_ATTRS "HttpOnly;Secure;Version=1"
#define CLEAR_ATTRS "Max-Age=0;Version=1"
#define CLEAR_ATTRS "Version=1"

typedef struct {
    request_rec *r;
@@ -60,9 +60,11 @@ typedef struct {
 * @param attrs The string containing additional cookie attributes. If NULL, the
 *              DEFAULT_ATTRS will be used.
 * @param maxage If non zero, a Max-Age header will be added to the cookie.
 * @param ... A varargs array of zero or more (apr_table_t *) tables followed by NULL
 *            to which the cookies should be added.
 */
AP_DECLARE(apr_status_t) ap_cookie_write(request_rec * r, const char *name, const char *val,
                                         const char *attrs, long maxage);
                                         const char *attrs, long maxage, ...);

/**
 * Write an RFC2965 compliant cookie.
@@ -73,9 +75,11 @@ AP_DECLARE(apr_status_t) ap_cookie_write(request_rec * r, const char *name, cons
 * @param attrs2 The string containing additional cookie attributes. If NULL, the
 *               DEFAULT_ATTRS will be used.
 * @param maxage If non zero, a Max-Age header will be added to the cookie.
 * @param ... A varargs array of zero or more (apr_table_t *) tables followed by NULL
 *            to which the cookies should be added.
 */
AP_DECLARE(apr_status_t) ap_cookie_write2(request_rec * r, const char *name2, const char *val,
                                          const char *attrs2, long maxage);
                                          const char *attrs2, long maxage, ...);

/**
 * Remove an RFC2109 compliant cookie.
@@ -84,8 +88,10 @@ AP_DECLARE(apr_status_t) ap_cookie_write2(request_rec * r, const char *name2, co
 * @param name The name of the cookie.
 * @param attrs The string containing additional cookie attributes. If NULL, the
 *              CLEAR_ATTRS will be used.
 * @param ... A varargs array of zero or more (apr_table_t *) tables followed by NULL
 *            to which the cookies should be added.
 */
AP_DECLARE(apr_status_t) ap_cookie_remove(request_rec * r, const char *name, const char *attrs);
AP_DECLARE(apr_status_t) ap_cookie_remove(request_rec * r, const char *name, const char *attrs, ...);

/**
 * Remove an RFC2965 compliant cookie.
@@ -94,8 +100,10 @@ AP_DECLARE(apr_status_t) ap_cookie_remove(request_rec * r, const char *name, con
 * @param name2 The name of the cookie.
 * @param attrs2 The string containing additional cookie attributes. If NULL, the
 *               CLEAR_ATTRS will be used.
 * @param ... A varargs array of zero or more (apr_table_t *) tables followed by NULL
 *            to which the cookies should be added.
 */
AP_DECLARE(apr_status_t) ap_cookie_remove2(request_rec * r, const char *name2, const char *attrs2);
AP_DECLARE(apr_status_t) ap_cookie_remove2(request_rec * r, const char *name2, const char *attrs2, ...);

/**
 * Read a cookie called name, placing its value in val.
+4 −4
Changes for modules/session/mod_session_cookie.c: 4 added lines, 4 removed lines.
Original line number Diff line number Diff line
@@ -67,20 +67,20 @@ static int session_cookie_save(request_rec * r, session_rec * z)
    /* create RFC2109 compliant cookie */
    if (conf->name_set) {
        if (z->encoded && z->encoded[0]) {
            ap_cookie_write(r, conf->name, z->encoded, conf->name_attrs, z->maxage);
            ap_cookie_write(r, conf->name, z->encoded, conf->name_attrs, z->maxage, r->headers_out, r->err_headers_out, NULL);
        }
        else {
            ap_cookie_remove(r, conf->name, conf->name_attrs);
            ap_cookie_remove(r, conf->name, conf->name_attrs, r->headers_out, r->err_headers_out, NULL);
        }
    }

    /* create RFC2965 compliant cookie */
    if (conf->name2_set) {
        if (z->encoded && z->encoded[0]) {
            ap_cookie_write2(r, conf->name2, z->encoded, conf->name2_attrs, z->maxage);
            ap_cookie_write2(r, conf->name2, z->encoded, conf->name2_attrs, z->maxage, r->headers_out, r->err_headers_out, NULL);
        }
        else {
            ap_cookie_remove2(r, conf->name2, conf->name2_attrs);
            ap_cookie_remove2(r, conf->name2, conf->name2_attrs, r->headers_out, r->err_headers_out, NULL);
        }
    }

+2 −2
Changes for modules/session/mod_session_dbd.c: 2 added lines, 2 removed lines.
Original line number Diff line number Diff line
@@ -431,12 +431,12 @@ static int session_dbd_save(request_rec * r, session_rec * z)

        /* create RFC2109 compliant cookie */
        if (conf->name_set) {
            ap_cookie_write(r, conf->name, buffer, conf->name_attrs, z->maxage);
            ap_cookie_write(r, conf->name, buffer, conf->name_attrs, z->maxage, r->headers_out, r->err_headers_out, NULL);
        }

        /* create RFC2965 compliant cookie */
        if (conf->name2_set) {
            ap_cookie_write2(r, conf->name2, buffer, conf->name2_attrs, z->maxage);
            ap_cookie_write2(r, conf->name2, buffer, conf->name2_attrs, z->maxage, r->headers_out, r->err_headers_out, NULL);
        }

        return OK;
Loading