Skip to content

Allow cookies in token_source_priority #75

Description

@allen0099

SessionConfig.token_source_priority accepts only "header" and "bearer". Cookie transport is read solely by FastAPICacheXSessionMiddleware, and the response side is a binary decision driven by where the token came from.

Folding cookies into the same priority list today would let ["cookie"] fail silently on the deprecated SessionMiddleware, which has no cookie support. Once #69 removes that class, one priority list can describe all three sources. See docs/SESSION.md.

Proposal

  • Extend the literal to Literal["header", "bearer", "cookie"].
  • Make the middleware resolve the token by walking the list, and set/clear the cookie on the response according to the source that was used.

Blocked by: #69

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    breaking-changeChanges public behaviour or API; needs a minor/major releaseenhancementNew feature or requestsessionSession management subsystem

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions