X-Git-Url: http://git.shadowcat.co.uk/gitweb/gitweb.cgi?p=catagits%2FCatalyst-Plugin-Session-State-Cookie.git;a=blobdiff_plain;f=lib%2FCatalyst%2FPlugin%2FSession%2FState%2FCookie.pm;h=dfd10bd038649dc31a39aab358aeaef2f6ad719d;hp=0c264901a0e8fd9643a1390309885d50066516e4;hb=e94e9e1c035e1687eb3a8c5758f1005ecf560495;hpb=3c6b745109624dae69d5de98cac74f09a9889e4b diff --git a/lib/Catalyst/Plugin/Session/State/Cookie.pm b/lib/Catalyst/Plugin/Session/State/Cookie.pm index 0c26490..dfd10bd 100644 --- a/lib/Catalyst/Plugin/Session/State/Cookie.pm +++ b/lib/Catalyst/Plugin/Session/State/Cookie.pm @@ -7,7 +7,7 @@ extends 'Catalyst::Plugin::Session::State'; use MRO::Compat; use Catalyst::Utils (); -our $VERSION = "0.13"; +our $VERSION = "0.17"; has _deleted_session_id => ( is => 'rw' ); @@ -16,7 +16,7 @@ sub setup_session { $c->maybe::next::method(@_); - $c->config->{session}{cookie_name} + $c->_session_plugin_config->{cookie_name} ||= Catalyst::Utils::appprefix($c) . '_session'; } @@ -42,7 +42,7 @@ sub update_session_cookie { my ( $c, $updated ) = @_; unless ( $c->cookie_is_rejecting( $updated ) ) { - my $cookie_name = $c->config->{session}{cookie_name}; + my $cookie_name = $c->_session_plugin_config->{cookie_name}; $c->response->cookies->{$cookie_name} = $updated; } } @@ -60,7 +60,7 @@ sub cookie_is_rejecting { sub make_session_cookie { my ( $c, $sid, %attrs ) = @_; - my $cfg = $c->config->{session}; + my $cfg = $c->_session_plugin_config; my $cookie = { value => $sid, ( $cfg->{cookie_domain} ? ( domain => $cfg->{cookie_domain} ) : () ), @@ -77,8 +77,9 @@ sub make_session_cookie { $cookie->{secure} = 1 unless ( ($sec==0) || ($sec==2) ); $cookie->{secure} = 1 if ( ($sec==2) && $c->req->secure ); + $cookie->{httponly} = $cfg->{cookie_httponly}; $cookie->{httponly} = 1 - unless exists $cookie->{httponly}; # default = 1 (set httponly) + unless defined $cookie->{httponly}; # default = 1 (set httponly) return $cookie; } @@ -90,7 +91,7 @@ sub calc_expiry { # compat sub calculate_session_cookie_expires { my $c = shift; - my $cfg = $c->config->{session}; + my $cfg = $c->_session_plugin_config; my $value = $c->maybe::next::method(@_); return $value if $value; @@ -111,7 +112,7 @@ sub calculate_session_cookie_expires { sub get_session_cookie { my $c = shift; - my $cookie_name = $c->config->{session}{cookie_name}; + my $cookie_name = $c->_session_plugin_config->{cookie_name}; return $c->request->cookies->{$cookie_name}; } @@ -231,14 +232,14 @@ user's browser is shut down. If this attribute B the cookie will not have the secure flag. If this attribute B (or true for backward compatibility) - the cookie -send by the server to the client will got the secure flag that tells the browser -to send this cookies back to the server only via HTTPS. +sent by the server to the client will get the secure flag that tells the browser +to send this cookie back to the server only via HTTPS. -If this attribute B then the cookie will got the secure flag only if +If this attribute B then the cookie will get the secure flag only if the request that caused cookie generation was sent over https (this option is -not good if you are mixing https and http in you application). +not good if you are mixing https and http in your application). -Default vaule is 0. +Default value is 0. =item cookie_httponly @@ -255,7 +256,7 @@ Default value is 1. Note1: Many peole are confused by the name "HTTPOnly" - it B that this cookie works only over HTTP and not over HTTPS. -Note2: This paramater requires Catalyst::Runtime 5.80005 otherwise is skipped. +Note2: This parameter requires Catalyst::Runtime 5.80005 otherwise is skipped. =item cookie_path @@ -265,7 +266,7 @@ The path of the request url where cookie should be baked. For example, you could stick this in MyApp.pm: - __PACKAGE__->config( session => { + __PACKAGE__->config( 'Plugin::Session' => { cookie_domain => '.mydomain.com', }); @@ -302,9 +303,16 @@ has been heavily modified since. Marcus Ramberg Jonathan Rockway Ejrockway@cpan.orgE Sebastian Riedel + Florian Ragwitz =head1 COPYRIGHT +Copyright (c) 2005 - 2009 +the Catalyst::Plugin::Session::State::Cookie L and L +as listed above. + +=head1 LICENSE + This program is free software, you can redistribute it and/or modify it under the same terms as Perl itself.