Skip to content

fix(Plugs.Cookies): avoid using other paths - #3385

Open
thecristen wants to merge 2 commits into
mainfrom
cbj/route-cookies-path
Open

fix(Plugs.Cookies): avoid using other paths#3385
thecristen wants to merge 2 commits into
mainfrom
cbj/route-cookies-path

Conversation

@thecristen

Copy link
Copy Markdown
Collaborator

Scope

Just happened to discover a few other "routes" stored in the cookie. :(

Implementation

It was thanks to poor path parsing. We have, for example, /schedules/map_api which one could hit. This would store "map_api" as a "route", which would eventually be looked up in Routes.Repo when rendering "Recently Visited" routes. Not great, and a waste of resources.

The other aspect of this I wanted to raise is that, if you happen to have a nonsensical route in your cookie, this is going to be requested from the V3 API over and over and over. This is because we don't cache error responses. Normally that's a good thing, but in light of recognizing our website gets hammered with excess requests.... this creates a suboptimal situation. So I added an extra change in Routes.Repo which caches errors, but only for 30 seconds. Curious what folks think of that.

Screenshots

No change!

How to test

The final test I added in the test file fails on main but passes here!

@thecristen
thecristen requested a review from a team as a code owner July 31, 2026 21:34
@thecristen
thecristen requested a review from jlucytan July 31, 2026 21:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant