fix(session): clear inactive sessions and batch session sweeps - #208
Merged
Merged
Conversation
clear_expired_sessions() only looked at expires_at, so records already marked INVALIDATED (invalidate_session) or EXPIRED (an expired read) stayed in the backend until their TTL ran out. Treat any record that is no longer ACTIVE as removable too. Both clear_expired_sessions() and delete_user_sessions() now collect the matching keys and remove them with one backend.delete_many() call instead of one sequential delete per session; the count comes from delete_many. Closes #165
20 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #165
Problem
clear_expired_sessions()only checkedexpires_at. A record already markedINVALIDATED(byinvalidate_session()) orEXPIRED(by an expired read) is unusable, yet it stayed in the backend until its TTL ran out. Repro: create a session, invalidate it, then callclear_expired_sessions(). It returns0and the key remains.clear_expired_sessions()anddelete_user_sessions()sent one sequentialdeleteper session.Fix
clear_expired_sessions()now removes any session whose status is notACTIVE, as well as any session pastexpires_at.backend.delete_many()call. The returned count comes fromdelete_many. On memory and Redis, that is what was actually removed. On the base fallback, it is what was attempted.docs/SESSION.mdand zh-TW describe whatclear_expired_sessions()removes and the single batch delete.Tests
test_clear_expired_sessions_removes_sessions_no_longer_active[invalidated|expired]test_session_sweeps_delete_in_one_batch: each sweep makes exactly onedelete_manycall with the right number of keys, and no per-keydeletecalls.manager.pychange reverted, exactly these 3 tests fail (208 others pass).mypy --strict, and the full suite against live Redis and Memcached (CACHEX_REQUIRE_LIVE_SERVERS=1): 864 passed.CHANGELOG entry
Section: Fixed (added to
CHANGELOG.mdvia #206)