This project is archived and is in readonly mode.
Session Cookie breaks if used with custom cookie in rails 2.3.8
-
Noah
- Tag set to rails 2.3.8, bug, cookie_store, session
-
Jesse Storimer
The issue is due to a change in Rack. Though the responsibility lies with Rails I think.
In ActionController::Response#convert_cookies! the Set-Cookie header is converted to an Array. ActionController then calls Response#finish before returning the response object. In Rack 1.0.1 #finish called Rack::Utils#to_hash on the header hash. This changed all of the values in the header hash to strings, undoing the change made by ActionController. Subsequently the CookieStore was expecting to receive a string and prepending a \n.
In Rack 1.1 #finish doesn't touch the headers, it leaves them as they are. So Rails converts the Set-Cookie header to an Array and its still an array when it gets back up to the CookieStore, so there's no need to prepend a \n.
This is the Rack commit with the change: http://github.com/rack/rack/commit/8f836f406ca10274c6465e17c2b56462...
-
Jesse Storimer
- Tag changed from rails 2.3.8, bug, cookie_store, session to rails 2.3.8, bug, cookie_store, patch, session
-
TMorgan99
I have posted a patch on ticket #99 SQLite connection failing in rack.
Please apply the patch and retest; it appears to have cleared my issue. -
Noah
Jesse -
That works. Any reason you're interpolating the cookie? Is it not a string already?
-
Jesse Storimer
So my patch solved the issue but it produced some weird behaviour.
ActionController::Response#convert_cookies!converts theSet-Cookieheader to an array if there are any cookies in there, if not, it just leaves it asnil.In my patch above, if there is already an existing cookie array the
CookieStorewill append the session cookie to that array. If theSet-Cookieheader is empty then theCookieStorewill assign it the value of the cookie.So in one case the value of
Set-Cookieis an Array, in the other case its a String. That seems wrong. SinceActionController::Response#convert_cookies!sets the header to an array I will ensure that thats preserved up the middleware stack inCookieStore. Patch attached.@Noah: interpolation removed. Thanks for noticing.
@TMorgan99: Applying that patch fixes the problem, but it fixes the wrong thing. Rack is not the culprit here. Check the commit message of rack/8f836f406ca10274c6465e17c2b5646257a8412b, it's a good patch. It's up to Rails to update its own middleware to work with the new changes in Rack.
-
Brian Hogan
This seems to work for my apps as well. Can we get this looked at by core ASAP?
-
Jeremy Kemper
- Milestone set to 2.3.9
- Assigned user set to josh
-
Aaron Gibralter
A temporary hack: http://gist.github.com/431811
-
Gravis
@Aaron: Thanks, the gist saved me a lot a time. It fixed an issue with cucumber-rails as well : http://github.com/aslakhellesoy/cucumber-rails/issues/#issue/40
-
Repository
- State changed from open to resolved
(from [85b6d79d8a17fdef667770e31b44ac6647f8b584]) CookieStore should preserve the Set-Cookie header Array [#4743 Session Cookie breaks if used with custom cookie in rails 2.3.8 state:resolved]
Signed-off-by: Jeremy Kemper jeremy@bitsweat.net
http://github.com/rails/rails/commit/85b6d79d8a17fdef667770e31b44ac... -
omarqureshi
Just had a very similar bug with ARStore - https://rails.lighthouseapp.com/projects/8994-ruby-on-rails/tickets...
The fix is similar, perhaps the code which sets the cookie needs to be pulled out into its own method which can be then reused by both?
What do you guys think?
