@@ -917,7 +917,7 @@ describe('session()', function(){
917917 this . server = createServer ( setup , { cookie : { secure : false , sameSite : 'auto' } } , respond )
918918 } )
919919
920- it ( 'should set both Secure and SameSite=None when secure' , function ( done ) {
920+ it ( 'should set SameSite=None without Secure when secure' , function ( done ) {
921921 request ( this . server )
922922 . get ( '/' )
923923 . set ( 'X-Secure' , 'true' )
@@ -926,7 +926,7 @@ describe('session()', function(){
926926 . expect ( 200 , 'true' , done )
927927 } )
928928
929- it ( 'should set neither Secure nor SameSite=None when insecure' , function ( done ) {
929+ it ( 'should set SameSite=Lax without Secure when insecure' , function ( done ) {
930930 request ( this . server )
931931 . get ( '/' )
932932 . set ( 'X-Secure' , 'false' )
@@ -958,12 +958,11 @@ describe('session()', function(){
958958 . expect ( 200 , 'true' , done )
959959 } )
960960
961- it . only ( 'should set neither Secure nor SameSite=None when insecure' , function ( done ) {
961+ it ( 'should not set cookie when insecure' , function ( done ) {
962962 request ( this . server )
963963 . get ( '/' )
964964 . set ( 'X-Secure' , 'false' )
965- . expect ( shouldSetCookieWithoutAttribute ( 'connect.sid' , 'Secure' ) )
966- . expect ( shouldSetCookieWithAttributeAndValue ( 'connect.sid' , 'SameSite' , 'Lax' ) )
965+ . expect ( shouldNotHaveHeader ( 'Set-Cookie' ) )
967966 . expect ( 200 , 'false' , done )
968967 } )
969968 } )
0 commit comments