Skip to content

examples/session_login.py: the new-visitor login sends its session cookie without Cache-Control: private, no-store #322

Description

@allen0099

Problem

In examples/session_login.py, the "new visitor logs in" branch creates the session and calls response.set_cookie itself. The middleware adds Cache-Control: private, no-store only to tokens it sends, so this response goes out without it:

POST /login (new visitor) -> 200
set-cookie: session=...; HttpOnly; Max-Age=1209600; Path=/; SameSite=lax
(no Cache-Control)

A shared cache or CDN could store the response and hand the login to the next visitor.

The same branch also:

  • leaves out domain=config.cookie_domain, so with a domain configured, the expiring cookie sent on logout does not match;
  • gives header/API clients a cookie but no token.

Proposal

Fix the example: send Cache-Control: private, no-store, pass the configured cookie attributes, and return the token for header clients. #293 would replace this code with a supported login(); until then the example is what people copy.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingdocumentationImprovements or additions to documentationsecuritySecurity vulnerability or hardeningsessionSession management subsystem

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions