Found during the docs audit (#360).
SessionConfig.cookie_max_age is described as "Max-Age (seconds) for the session cookie; None disables Max-Age/Expires", but the middleware tests it for truthiness (fastapi_cachex/session/middleware.py:656-660):
cookie_max_age=0 behaves exactly like None (no Max-Age, a browser-session cookie), although Max-Age=0 would normally mean "expire now";
- negative values are accepted and sent as
Max-Age=-5.
SESSION.md now documents that 0 omits Max-Age. Options: validate cookie_max_age as None or a positive int (0/negative rejected, possibly with a deprecation step first), or keep 0 as an alias of None and say so in the field description. Either way, reject negatives.
Found during the docs audit (#360).
SessionConfig.cookie_max_ageis described as "Max-Age (seconds) for the session cookie; None disables Max-Age/Expires", but the middleware tests it for truthiness (fastapi_cachex/session/middleware.py:656-660):cookie_max_age=0behaves exactly likeNone(noMax-Age, a browser-session cookie), althoughMax-Age=0would normally mean "expire now";Max-Age=-5.SESSION.md now documents that
0omitsMax-Age. Options: validatecookie_max_ageasNoneor a positive int (0/negative rejected, possibly with a deprecation step first), or keep0as an alias ofNoneand say so in the field description. Either way, reject negatives.