Problem
Under FastAPICacheXSessionMiddleware, any visitor who reaches an endpoint that writes to request.session (a cart, a CSRF value) gets an anonymous session with user=None. get_session, RequiredSession and UserSessionDep only check that a session exists, so an app using them as an authentication guard admits anonymous visitors. UserSessionDep's name suggests otherwise.
Proposal
- Add
require_user_session (and an annotated alias) that raises 401 when session.user is None.
- Document the difference in SESSION.md.
- Making
UserSessionDep enforce a user is breaking and tracked for 0.4.0.
Problem
Under
FastAPICacheXSessionMiddleware, any visitor who reaches an endpoint that writes torequest.session(a cart, a CSRF value) gets an anonymous session withuser=None.get_session,RequiredSessionandUserSessionDeponly check that a session exists, so an app using them as an authentication guard admits anonymous visitors.UserSessionDep's name suggests otherwise.Proposal
require_user_session(and an annotated alias) that raises 401 whensession.user is None.UserSessionDepenforce a user is breaking and tracked for 0.4.0.