Commit f2cdf241 authored by Jan Koester's avatar Jan Koester
Browse files

test

parent 13f880a5
Loading
Loading
Loading
Loading
+32 −0
Original line number Diff line number Diff line
@@ -3392,6 +3392,38 @@ void blogi::Blogi::RequestEvent(libhttppp::HttpRequest &curreq, const int tid, U

                if (!found)
                {
                    // Consent hasn't been given yet, so the page still renders
                    // with the banner overlay instead of redirecting/blocking --
                    // but every downstream handler for this request (including
                    // plugin Controllers, e.g. schimmeldoc's own /login) is
                    // handed this same `sessid`, and several of them assume a
                    // non-empty session id (see the "delSessionData Sessionid
                    // or key could not be zero!" bug report: a first-time
                    // visitor with no consent-cookie fields in the request
                    // reached a login handler with sessid=="" and crashed).
                    // A technical session id is not itself a consent-gated
                    // cookie (no CookieBanner permissions are granted here,
                    // same as the "found" branch further down never grants any
                    // beyond what the submitted form says) -- it's the site
                    // working at all. So create and persist one here too,
                    // exactly like the "found" branch does, just without its
                    // PRG redirect (this request should still render normally).
                    std::string buf;
                    std::string usa;

                    libhttppp::HttpHeader::HeaderData *uahdr = curreq.getHeaderData("user-agent");
                    if (uahdr)
                    {
                        for (libhttppp::HttpHeader::HeaderData::Values *uval = uahdr->getfirstValue(); uval; uval = uval->nextvalue())
                        {
                            usa += uval->getvalue();
                            usa += "; ";
                        }
                    }

                    sessid = sess.createSession(buf, usa);
                    cookie.setcookie(curres, "sessionid", sessid, "", cookieDomain(curreq).c_str(), (1000 * 60 * 60 * 1), "/", false, "1", "Lax", false);

                    std::string _clang = getLang(*PlgArgs->database[tid]);
                    blogi::print(*PlgArgs->database[tid], _clang, curreq.getRequestURL(), index, ctx->cookieEl);
                }