Problem
In examples/session_login.py, the "new visitor logs in" branch creates the session and calls response.set_cookie itself. The middleware adds Cache-Control: private, no-store only to tokens it sends, so this response goes out without it:
POST /login (new visitor) -> 200
set-cookie: session=...; HttpOnly; Max-Age=1209600; Path=/; SameSite=lax
(no Cache-Control)
A shared cache or CDN could store the response and hand the login to the next visitor.
The same branch also:
- leaves out
domain=config.cookie_domain, so with a domain configured, the expiring cookie sent on logout does not match;
- gives header/API clients a cookie but no token.
Proposal
Fix the example: send Cache-Control: private, no-store, pass the configured cookie attributes, and return the token for header clients. #293 would replace this code with a supported login(); until then the example is what people copy.
Problem
In
examples/session_login.py, the "new visitor logs in" branch creates the session and callsresponse.set_cookieitself. The middleware addsCache-Control: private, no-storeonly to tokens it sends, so this response goes out without it:A shared cache or CDN could store the response and hand the login to the next visitor.
The same branch also:
domain=config.cookie_domain, so with a domain configured, the expiring cookie sent on logout does not match;Proposal
Fix the example: send
Cache-Control: private, no-store, pass the configured cookie attributes, and return the token for header clients. #293 would replace this code with a supportedlogin(); until then the example is what people copy.