Skip to content

SessionConfig.cookie_max_age: 0 acts like None and negative values are not validated #365

Description

@allen0099

Found during the docs audit (#360).

SessionConfig.cookie_max_age is described as "Max-Age (seconds) for the session cookie; None disables Max-Age/Expires", but the middleware tests it for truthiness (fastapi_cachex/session/middleware.py:656-660):

  • cookie_max_age=0 behaves exactly like None (no Max-Age, a browser-session cookie), although Max-Age=0 would normally mean "expire now";
  • negative values are accepted and sent as Max-Age=-5.

SESSION.md now documents that 0 omits Max-Age. Options: validate cookie_max_age as None or a positive int (0/negative rejected, possibly with a deprecation step first), or keep 0 as an alias of None and say so in the field description. Either way, reject negatives.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingsessionSession management subsystem

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions