• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

go-pkgz / auth
87%
master: 87%

Build:
Build:
LAST BUILD BRANCH: feat/partitioned-cookies
DEFAULT BRANCH: master
Repo Added 26 Dec 2018 08:17AM UTC
Files 25
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

LAST BUILD ON BRANCH feat/partitioned-cookies
branch: SELECT
CHANGE BRANCH
x
  • No branch selected
  • allowed-provider-check
  • apple-reponse-mode-fix
  • aud-secrets
  • ava-factory
  • avatar-errnotfound
  • chore/go-fix
  • ci/codeql-v2
  • ci/go-1.26-golangci-2.12
  • configurable-microsoft-tenant
  • cookie-domain
  • custom-dev-host
  • custom-dev-port
  • dependabot/go_modules/_example/github.com/go-chi/chi/v5-5.2.2
  • dependabot/go_modules/_example/golang.org/x/crypto-0.17.0
  • dependabot/go_modules/_example/golang.org/x/image-0.38.0
  • dependabot/go_modules/_example/golang.org/x/image-0.5.0
  • dependabot/go_modules/_example/golang.org/x/net-0.17.0
  • dependabot/go_modules/_example/golang.org/x/net-0.7.0
  • dependabot/go_modules/golang.org/x/crypto-0.31.0
  • dependabot/go_modules/golang.org/x/image-0.38.0
  • dependabot/go_modules/golang.org/x/image-0.41.0
  • dependabot/go_modules/v2/github.com/golang-jwt/jwt/v5-5.2.2
  • dependabot/go_modules/v2/golang.org/x/crypto-0.31.0
  • dependabot/go_modules/v2/golang.org/x/crypto-0.45.0
  • dependabot/go_modules/v2/golang.org/x/crypto-0.52.0
  • dependabot/go_modules/v2/golang.org/x/image-0.41.0
  • dependabot/go_modules/v2/golang.org/x/net-0.33.0
  • dependabot/go_modules/v2/golang.org/x/net-0.36.0
  • deps-refresh
  • direct-custom-id
  • docs/comment-sweep
  • docs/microsoft-signin-audience
  • dverhoturov/telegram_fix
  • email-send-context
  • email-sender
  • feat/csrf-middleware
  • feat/github-numeric-id
  • feat/partitioned-cookies
  • feat/sender-helo-host
  • feat/telegram-api-url
  • feature/custom-error-handler
  • fix-anon
  • fix-content-type-header
  • fix-oauth-from-open-redirect
  • fix-oauth-sendjwtheader
  • fix-providers-names
  • fix/admin-passwd-log-leak
  • fix/apple-id-token-iss-aud
  • fix/apple-jwk-cache
  • fix/apple-log-redact-token-response
  • fix/auth-sensitive-logging
  • fix/avatar-content-type-spoofing-xss
  • fix/csp-consumer-note
  • fix/dev-custom-bind-localhost
  • fix/documented-auth-params
  • fix/email-sender-redact-body
  • fix/go127-image-assertions
  • fix/go127-test-assertions
  • fix/gridfs-concurrent-put
  • fix/gridfs-revisions
  • fix/nil-avatar-store
  • fix/panic-save-ava-nil
  • fix/see-other-redirect-after-auth
  • fix/telegram-redact-bot-token-in-avatar-url
  • fix/v1-from-redirect-validator
  • fix/verify-replay
  • fix/verify-replay-typed-nil-followup
  • followups/security-review
  • github-enterprise-provider
  • go1_20
  • jwt-header
  • master
  • microsoft
  • migrate-example-to-routegroup
  • no-ava
  • official-mongo-drvier
  • paskal/HttpOnly
  • paskal/add_common_processor
  • paskal/avatar_return_proper_content_type
  • paskal/bump_ci_go_version
  • paskal/bump_dep
  • paskal/bump_go_modules
  • paskal/bump_modules
  • paskal/double_close
  • paskal/email_module
  • paskal/facelift
  • paskal/fix_actions_test
  • paskal/fix_apple_key_panic
  • paskal/fix_custom_server
  • paskal/fix_error
  • paskal/fix_golangcilint
  • paskal/fix_lint_report
  • paskal/fix_send_jwt_header
  • paskal/google_auth_doc
  • paskal/improve_telegram
  • paskal/modules_bump
  • paskal/mongodb
  • paskal/moq
  • paskal/new_errors
  • paskal/plain_text
  • paskal/switch_to_v2
  • paskal/sync_v2
  • paskal/telegram_site_id
  • paskal/tg_username
  • paskal/token_generation_instructions
  • paskal/update-dependencies
  • paskal/update-modules
  • paskal/update_modules
  • paskal/update_pkcs8
  • paskal/v2
  • paskal/v2_golangcilint
  • paskal/v2_jwt5
  • ps/fix-example
  • rbac
  • refs/tags/v0.10.0
  • refs/tags/v0.10.1
  • refs/tags/v0.10.2
  • refs/tags/v0.11.0
  • refs/tags/v0.12.0
  • refs/tags/v0.12.1
  • refs/tags/v1.13.0
  • refs/tags/v1.13.1
  • refs/tags/v1.14.0
  • refs/tags/v1.15.0
  • refs/tags/v1.16.0
  • refs/tags/v1.17.0
  • refs/tags/v1.18.0
  • refs/tags/v1.19.0
  • refs/tags/v1.19.1
  • refs/tags/v1.20.0
  • refs/tags/v1.21.0
  • refs/tags/v1.22.0
  • refs/tags/v1.22.1
  • refs/tags/v1.23.0
  • refs/tags/v1.24.0
  • refs/tags/v1.24.1
  • refs/tags/v1.24.2
  • refs/tags/v1.25.1
  • refs/tags/v1.25.2
  • refs/tags/v1.25.3
  • refs/tags/v1.25.4
  • refs/tags/v1.25.5
  • refs/tags/v1.25.6
  • refs/tags/v1.25.7
  • refs/tags/v1.26.0
  • refs/tags/v1.27.0
  • refs/tags/v1.5.1
  • refs/tags/v2.0.0
  • refs/tags/v2.1.0
  • refs/tags/v2.1.1
  • refs/tags/v2.1.2
  • refs/tags/v2.1.3
  • refs/tags/v2.1.4
  • refs/tags/v2.1.5
  • refs/tags/v2.1.6
  • refs/tags/v2.1.7
  • refs/tags/v2.2.0
  • refs/tags/v2.3.0
  • remove-bluemonday
  • samesite
  • sanitize-verifyed
  • update-dependencies-2026-04
  • update-dependencies-dec2024
  • update-deps-and-golangci-v2
  • upgrade-repeater-v2
  • v0.8.0
  • v0.8.1
  • v0.8.2
  • v0.8.3
  • v0.9.0
  • verify-avatar

04 Sep 2026 08:31AM UTC coverage: 86.727% (+0.06%) from 86.663%
33853851331

Pull #318

github

paskal
Add PartitionedCookies for third-party (CHIPS) deployments

An auth cookie set from an embedded context is dropped by browsers
enforcing CHIPS unless it carries the Partitioned attribute. The option
threads through Opts to the token service and onto both the JWT and XSRF
cookies, and it is opt-in: nothing changes for a first-party deployment.

Partitioned only means anything alongside Secure and SameSite=None, so
setting it without Secure logs a warning instead of emitting a cookie the
browser will reject. Switching a deployment on also leaves an unpartitioned
cookie behind under the same name, so the reset path clears the legacy pair
as well as the new one.

The plumbing test exists because the token.Opts literal in NewService has
silently dropped a field twice, bd39e5e3 for SameSite and 59656e46 for
XSRFIgnoreMethods, both in diffs shaped exactly like this one: a re-indent
plus one added key. Neither failed a test, because nothing asserted the
plumbing rather than the behaviour.

The avatar assertion goes the same way: the identicon test proved a PNG
came back, not that it depended on the user, so a generator returning one
fixed image would have passed it.
Pull Request #318: Add PartitionedCookies so an embedded app can keep an HttpOnly session

46 of 46 new or added lines in 2 files covered. (100.0%)

3352 of 3865 relevant lines covered (86.73%)

9.92 hits per line

Relevant lines Covered
Build:
Build:
3865 RELEVANT LINES 3352 COVERED LINES
9.92 HITS PER LINE
Source Files on master
  • Tree
  • List 25
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line

Recent builds

Builds Branch Commit Type Ran Committer Via Coverage
33853851331 feat/partitioned-cookies Add PartitionedCookies for third-party (CHIPS) deployments An auth cookie set from an embedded context is dropped by browsers enforcing CHIPS unless it carries the Partitioned attribute. The option threads through Opts to the token service and on... Pull #318 04 Sep 2026 08:33AM UTC paskal github
86.73
33853851311 feat/partitioned-cookies Add PartitionedCookies for third-party (CHIPS) deployments An auth cookie set from an embedded context is dropped by browsers enforcing CHIPS unless it carries the Partitioned attribute. The option threads through Opts to the token service and on... Pull #318 04 Sep 2026 08:33AM UTC paskal github
86.74
33853175099 feat/partitioned-cookies Add PartitionedCookies for third-party (CHIPS) deployments An auth cookie set from an embedded context is dropped by browsers enforcing CHIPS unless it carries the Partitioned attribute. The option threads through Opts to the token service and on... Pull #318 04 Sep 2026 08:25AM UTC paskal github
86.62
33853174974 feat/partitioned-cookies Add PartitionedCookies for third-party (CHIPS) deployments An auth cookie set from an embedded context is dropped by browsers enforcing CHIPS unless it carries the Partitioned attribute. The option threads through Opts to the token service and on... Pull #318 04 Sep 2026 08:25AM UTC paskal github
86.58
33284994313 refs/tags/v2.3.0 fix: remove the data race and the order dependence in the telegram tests setupHandler returned context.CancelFunc directly, so cleanup() returned while Run was still looping and TestTelegram_TokenVerification's unlocked write to requests.data rac... push 30 Aug 2026 01:10AM UTC umputun github
86.7
33284998273 refs/tags/v1.27.0 fix: remove the data race and the order dependence in the telegram tests setupHandler returned context.CancelFunc directly, so cleanup() returned while Run was still looping and TestTelegram_TokenVerification's unlocked write to requests.data rac... push 30 Aug 2026 01:10AM UTC umputun github
86.7
33284998170 refs/tags/v1.27.0 fix: remove the data race and the order dependence in the telegram tests setupHandler returned context.CancelFunc directly, so cleanup() returned while Run was still looping and TestTelegram_TokenVerification's unlocked write to requests.data rac... push 30 Aug 2026 01:10AM UTC umputun github
86.66
33284994312 refs/tags/v2.3.0 fix: remove the data race and the order dependence in the telegram tests setupHandler returned context.CancelFunc directly, so cleanup() returned while Run was still looping and TestTelegram_TokenVerification's unlocked write to requests.data rac... push 30 Aug 2026 01:10AM UTC umputun github
86.66
32999026580 master fix: remove the data race and the order dependence in the telegram tests setupHandler returned context.CancelFunc directly, so cleanup() returned while Run was still looping and TestTelegram_TokenVerification's unlocked write to requests.data rac... push 26 Aug 2026 06:20PM UTC umputun github
86.66
32999027869 master fix: remove the data race and the order dependence in the telegram tests setupHandler returned context.CancelFunc directly, so cleanup() returned while Run was still looping and TestTelegram_TokenVerification's unlocked write to requests.data rac... push 26 Aug 2026 06:20PM UTC umputun github
86.65
See All Builds (1260)
  • Repo on GitHub
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc