Loading src/blogi.cpp +32 −0 Original line number Diff line number Diff line Loading @@ -3392,6 +3392,38 @@ void blogi::Blogi::RequestEvent(libhttppp::HttpRequest &curreq, const int tid, U if (!found) { // Consent hasn't been given yet, so the page still renders // with the banner overlay instead of redirecting/blocking -- // but every downstream handler for this request (including // plugin Controllers, e.g. schimmeldoc's own /login) is // handed this same `sessid`, and several of them assume a // non-empty session id (see the "delSessionData Sessionid // or key could not be zero!" bug report: a first-time // visitor with no consent-cookie fields in the request // reached a login handler with sessid=="" and crashed). // A technical session id is not itself a consent-gated // cookie (no CookieBanner permissions are granted here, // same as the "found" branch further down never grants any // beyond what the submitted form says) -- it's the site // working at all. So create and persist one here too, // exactly like the "found" branch does, just without its // PRG redirect (this request should still render normally). std::string buf; std::string usa; libhttppp::HttpHeader::HeaderData *uahdr = curreq.getHeaderData("user-agent"); if (uahdr) { for (libhttppp::HttpHeader::HeaderData::Values *uval = uahdr->getfirstValue(); uval; uval = uval->nextvalue()) { usa += uval->getvalue(); usa += "; "; } } sessid = sess.createSession(buf, usa); cookie.setcookie(curres, "sessionid", sessid, "", cookieDomain(curreq).c_str(), (1000 * 60 * 60 * 1), "/", false, "1", "Lax", false); std::string _clang = getLang(*PlgArgs->database[tid]); blogi::print(*PlgArgs->database[tid], _clang, curreq.getRequestURL(), index, ctx->cookieEl); } Loading Loading
src/blogi.cpp +32 −0 Original line number Diff line number Diff line Loading @@ -3392,6 +3392,38 @@ void blogi::Blogi::RequestEvent(libhttppp::HttpRequest &curreq, const int tid, U if (!found) { // Consent hasn't been given yet, so the page still renders // with the banner overlay instead of redirecting/blocking -- // but every downstream handler for this request (including // plugin Controllers, e.g. schimmeldoc's own /login) is // handed this same `sessid`, and several of them assume a // non-empty session id (see the "delSessionData Sessionid // or key could not be zero!" bug report: a first-time // visitor with no consent-cookie fields in the request // reached a login handler with sessid=="" and crashed). // A technical session id is not itself a consent-gated // cookie (no CookieBanner permissions are granted here, // same as the "found" branch further down never grants any // beyond what the submitted form says) -- it's the site // working at all. So create and persist one here too, // exactly like the "found" branch does, just without its // PRG redirect (this request should still render normally). std::string buf; std::string usa; libhttppp::HttpHeader::HeaderData *uahdr = curreq.getHeaderData("user-agent"); if (uahdr) { for (libhttppp::HttpHeader::HeaderData::Values *uval = uahdr->getfirstValue(); uval; uval = uval->nextvalue()) { usa += uval->getvalue(); usa += "; "; } } sessid = sess.createSession(buf, usa); cookie.setcookie(curres, "sessionid", sessid, "", cookieDomain(curreq).c_str(), (1000 * 60 * 60 * 1), "/", false, "1", "Lax", false); std::string _clang = getLang(*PlgArgs->database[tid]); blogi::print(*PlgArgs->database[tid], _clang, curreq.getRequestURL(), index, ctx->cookieEl); } Loading