Skip to content

fix: keep config defaults for keys a config file omits - #120

Merged
m-t-a97 merged 3 commits into
Authula:mainfrom
rawsun007:fix/config-file-keeps-defaults
Oct 5, 2026
Merged

m-t-a97 merged 3 commits into
Authula:mainfrom
rawsun007:fix/config-file-keeps-defaults

Conversation

@rawsun007

Copy link
Copy Markdown
Contributor

The config loader decodes the TOML file into a zero Config and hands each section to the With* options. WithSession and WithSecurity copy some fields as given, so any config file, even one with no [session] section, ends up with:

  • session.http_only = false (default true), so the session cookie is readable from JavaScript
  • session.max_sessions_per_user = 0 (default 5), which disables the limit
  • security.cors.allow_credentials = false (default true)

Running with no config file keeps the defaults. That's why it doesn't show up in a quick local run.

The fix decodes the file on top of DefaultConfig(), the defaults NewConfig now starts from. A key the file omits keeps its default, and one it sets explicitly still wins. The new table-driven test in cmd/shared/configloader covers both. With the old loader, the two omitted-key cases fail.

Library users who call WithSession with a partial SessionConfig still get the zero values for those fields. Fixing that needs pointer fields or similar, which is an API decision I've left to you.

make format, go vet ./..., golangci-lint run (0 issues), make build and go test -race ./... (64 packages) all pass locally.

AI disclosure: written with Claude Code (Claude Opus 5.5). I reviewed the diff before opening this.

The loader decoded the TOML file into a zero Config and passed each
section to the With* options, which copy booleans and some ints as
given. So any config file, even one without a [session] section, turned
session.http_only off, set max_sessions_per_user to 0 (no limit) and
turned security.cors.allow_credentials off. Running with no file kept
the defaults.

Decode the file on top of DefaultConfig, the defaults NewConfig now
starts from, so an omitted key keeps its default and an explicit one
still wins.
@m-t-a97

m-t-a97 commented Oct 3, 2026

Copy link
Copy Markdown
Member

Thanks for the PR, will look into it soon.

@rawsun007

Copy link
Copy Markdown
Contributor Author

no worries, thanks bro

@m-t-a97 m-t-a97 added the bug Something isn't working label Oct 5, 2026
@m-t-a97
m-t-a97 merged commit bb82fa0 into Authula:main Oct 5, 2026
6 checks passed
@m-t-a97

m-t-a97 commented Oct 5, 2026

Copy link
Copy Markdown
Member

I pushed a few updates to this PR. I hope you don't mind.

Thanks again.

@rawsun007

Copy link
Copy Markdown
Contributor Author

np bro,
thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants