Rails 6 Session Data Not Persisting

Viewed 746

I've been battling this for about 24 hours now, and nothing I'm finding in my searches is leading to a solution.

My issue is my session data is not persisting and I can not log in to my app. Everything worked in Dev mode, but has not yet worked in Production. I'm using a Rails 6 Api hosted on Heroku and a React front end. I can successfully make the api call, find the user, and log them in using (I use "puts" to help me log the session at that instance. The session hash has a session_id and user_id at this point):

def login!
    session[:user_id] = @user.id
    puts "login_session: #{session.to_hash}"
end

After this the app redirects to the user page or an admin page depending on the users authorization.

When the redirect happens that the user or admin page calls the api to see if the user is authorized using:

def logged_in?
    puts "logged_in_session: #{session.to_hash}"
    !!session[:user_id]
end

The session is empty. Here is my sessions controller:

class SessionsController < ApplicationController

def create
    @user = User.find_by(email: session_params[:email])
    puts @user.inspect
    if @user && @user.authenticate(session_params[:password])
        
      login!
      render json: {
        logged_in: true,
        user: UserSerializer.new(@user)
      }
    else
      render json: { 
        status: 401,
        errors: ['no such user', 'verify credentials and try again or signup']
      }
    end
end


def is_logged_in?
    if logged_in? && current_user
      render json: {
        logged_in: true,
        user: UserSerializer.new(current_user)
      }
    else
      render json: {
        logged_in: false,
        message: 'no such user or you need to login'
      }
    end
end

def is_authorized_user?
    
    user = User.find(params[:user_id][:id])
    
    if user == current_user
        render json: {
            authorized: true
        }
    else
        render json:{
            authorized: false
        }
    end
end


def destroy
    logout!
    render json: {
      status: 200,
      logged_out: true
    }
end

def omniauth
  @user = User.from_omniauth(auth)
  @user.save
  login!
  render json: UserSerializer.new(@user)
end

private

def session_params
    params.require(:user).permit(:username, :email, :password)
end

def auth
    
    request.env['omniauth.auth']
end

Would any be able to point me the right direction??

Thank you

3 Answers

I would verify the following:

  1. When first authenticated, does the response from the endpoint include the cookie data?
  2. Check the cookie store in your browser (there's a few extensions you can use to make this easier) and verify that the domain names match and the content in the cookie is what you'd expect.
  3. You can cross reference the cookie ID with the ID in your session store (depending on where you've chosen to store this).
  4. Can you verify the cookie contents (user_id) and session contents in the session store.
  5. Make sure that the cookie data is being sent on the next request after authenticating (check the request headers in the network tab of your dev tools in the browser).

This is all assuming that you're using a browser to talk to this JSON endpoint. APIs usually don't use cookies as it's a browser thing. Alternative authentication mechanisms might be a short lived token (JWT for example) that is generated when authenticating that can be used for subsequent requests.

Quick update: I am able to get the "Set-Cookie: _session_id=..." in the response but it is blocked to due to "SameSite=lax" attribute.

I believe I need to change to SameSite = none, but I'm not sure were to do that.

Any advice?

A bit late but if you're using Rails 6 API, session has been disabled. You need to add the middleware manually. Here is the documentation using-session-middlewares

# This also configures session_options for use below
config.session_store :cookie_store, key: '_interslice_session'

# Required for all session management (regardless of session_store)
config.middleware.use ActionDispatch::Cookies

config.middleware.use config.session_store, config.session_options
Related