"""Training app for the cookie-flags lab. Runs on localhost only.
Run:  pip install flask   then   python cookie_app.py   then open http://localhost:5001/login
"""
import secrets
from flask import Flask, make_response, request

app = Flask(__name__)
SESSIONS = {}

@app.route("/login")
def login():
    sid = secrets.token_urlsafe(24)
    SESSIONS[sid] = "student01"
    resp = make_response("<h1>Logged in as student01</h1><p><a href='/profile'>Go to profile</a></p>")
    # TODO (lab): this session cookie has no security flags
    resp.set_cookie("session_id", sid)
    # a harmless preference cookie (no secret inside)
    resp.set_cookie("theme", "dark", samesite="Lax")
    return resp

@app.route("/profile")
def profile():
    user = SESSIONS.get(request.cookies.get("session_id", ""))
    return f"<h1>Profile</h1><p>User: {user or 'not logged in'}</p>"

if __name__ == "__main__":
    app.run(host="127.0.0.1", port=5001, debug=False)
