forked from mitre/HTTP-Proxy-Servlet
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathCookieSameSiteTest.java
More file actions
84 lines (75 loc) · 3.15 KB
/
Copy pathCookieSameSiteTest.java
File metadata and controls
84 lines (75 loc) · 3.15 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
/*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.mitre.dsmiley.httpproxy;
import static org.junit.Assert.assertNotNull;
import static org.junit.Assert.assertTrue;
import jakarta.servlet.ServletException;
import jakarta.servlet.http.HttpServlet;
import jakarta.servlet.http.HttpServletRequest;
import jakarta.servlet.http.HttpServletResponse;
import java.io.IOException;
import org.apache.http.Header;
import org.apache.http.client.methods.CloseableHttpResponse;
import org.apache.http.client.methods.HttpGet;
import org.apache.http.impl.client.CloseableHttpClient;
import org.apache.http.impl.client.HttpClientBuilder;
import org.eclipse.jetty.ee10.servlet.ServletContextHandler;
import org.eclipse.jetty.ee10.servlet.ServletHolder;
import org.eclipse.jetty.server.Server;
import org.eclipse.jetty.server.ServerConnector;
import org.junit.After;
import org.junit.Before;
import org.junit.Test;
public class CookieSameSiteTest {
private Server server;
private ServletContextHandler context;
private int serverPort;
@Before
public void setUp() throws Exception {
server = new Server(0);
context = new ServletContextHandler();
context.setContextPath("/");
server.setHandler(context);
server.start();
serverPort = ((ServerConnector) server.getConnectors()[0]).getLocalPort();
}
@After
public void tearDown() throws Exception {
server.stop();
serverPort = -1;
}
@Test
public void testSameSiteAttributeIsPreserved() throws Exception {
// Backend returns a cookie with SameSite=Strict
ServletHolder backendHolder = new ServletHolder(new HttpServlet() {
@Override
protected void doGet(HttpServletRequest req, HttpServletResponse resp)
throws ServletException, IOException {
resp.addHeader("Set-Cookie", "JSESSIONID=1234; Path=/backend; SameSite=Strict");
}
});
context.addServlet(backendHolder, "/backend/*");
ServletHolder proxyHolder = context.addServlet(ProxyServlet.class, "/proxy/*");
proxyHolder.setInitParameter(ProxyServlet.P_TARGET_URI,
String.format("http://localhost:%d/backend/", serverPort));
HttpGet request = new HttpGet(String.format("http://localhost:%d/proxy/test", serverPort));
try (CloseableHttpClient client = HttpClientBuilder.create().disableRedirectHandling().build();
CloseableHttpResponse response = client.execute(request)) {
Header setCookieHeader = response.getFirstHeader("Set-Cookie");
assertNotNull("Set-Cookie header must be present", setCookieHeader);
assertTrue("SameSite attribute must be preserved when proxying cookies",
setCookieHeader.getValue().contains("SameSite=Strict"));
}
}
}