mirror of
https://github.com/Kong/insomnia.git
synced 2026-10-07 21:44:10 -04:00
* fix: limit cookie template rendering to manually-set cookies and narrow template file access * fix: only expand nested templates for variable substitution, not direct tag output * test: cover OAuth2 access token exposure via the request tag for nested-template regression * sec: exclude response-sourced cookies from WebSocket/Socket.IO connect rendering * test: fix mTLS/cert smoke tests relying on secure-read-file path-prefix bug * test: scope mtls smoke test locator to avoid strict-mode collision * sec: close hard-link bypass of reserved NeDB database file check * fix: avoid doubled path separator when allowlisted folder is a filesystem root
41 lines
1.1 KiB
TypeScript
41 lines
1.1 KiB
TypeScript
import type { CookieJar } from 'insomnia-data';
|
|
import { v4 as uuidv4 } from 'uuid';
|
|
|
|
/** Ensure every cookie has an ID property */
|
|
function migrateCookieId(cookieJar: CookieJar) {
|
|
for (const cookie of cookieJar.cookies) {
|
|
if (!cookie.id) {
|
|
cookie.id = uuidv4();
|
|
}
|
|
}
|
|
|
|
return cookieJar;
|
|
}
|
|
|
|
/**
|
|
* Grandfather in cookies that predate the `source` field as 'manual', so cookies a user
|
|
* already relied on for template rendering keep working. Every write path introduced
|
|
* alongside `source` (network responses, imports, scripts) always sets it explicitly, so once
|
|
* a cookie has passed through this migration once, `source` should never go missing again.
|
|
*/
|
|
function migrateCookieSource(cookieJar: CookieJar) {
|
|
for (const cookie of cookieJar.cookies) {
|
|
if (!cookie.source) {
|
|
cookie.source = 'manual';
|
|
}
|
|
}
|
|
|
|
return cookieJar;
|
|
}
|
|
|
|
export function migrate(doc: CookieJar) {
|
|
try {
|
|
doc = migrateCookieId(doc);
|
|
doc = migrateCookieSource(doc);
|
|
return doc;
|
|
} catch (e) {
|
|
console.log('[db] Error during cookie jar migration', e);
|
|
throw e;
|
|
}
|
|
}
|