Files
chatwoot/spec/config/session_store_spec.rb
95d6aecb51 chore: Add security flags to session cookie configuration (#14248)
## Summary
- Adds `httponly` and `secure` flags to session cookie configuration
- Adds RSpec tests for session configuration

## Changes
- `config/initializers/session_store.rb`: add `httponly: true`, `secure:
FORCE_SSL`
- `spec/config/session_store_spec.rb`: tests for all session store
options

Ref #2683 (hardens the session cookie but does not remove it, sessions
are still needed for super_admin dashboard)

---------

Co-authored-by: Adam-Relay <adam@userelay.ai>
Co-authored-by: Adam Berger <adam@adam-berger.com>
Co-authored-by: Vishnu Narayanan <iamwishnu@gmail.com>
2026-06-11 16:13:57 +05:30

30 lines
850 B
Ruby

require 'rails_helper'
# rubocop:disable RSpec/DescribeClass
describe 'Session Store Configuration' do
# rubocop:enable RSpec/DescribeClass
let(:session_options) { Rails.application.config.session_options }
it 'uses cookie_store as the session store' do
expect(Rails.application.config.session_store).to eq(ActionDispatch::Session::CookieStore)
end
it 'sets the session key' do
expect(session_options[:key]).to eq('_chatwoot_session')
end
it 'sets same_site to lax' do
expect(session_options[:same_site]).to eq(:lax)
end
it 'sets httponly to true' do
expect(session_options[:httponly]).to be(true)
end
it 'sets secure flag based on FORCE_SSL' do
expected_secure = ActiveModel::Type::Boolean.new.cast(ENV.fetch('FORCE_SSL', false))
expect(session_options[:secure]).to eq(expected_secure)
end
end