Skip to content

fix(session): clear inactive sessions and batch session sweeps - #208

Merged
allen0099 merged 1 commit into
masterfrom
fix/session-clear-inactive
Sep 26, 2026
Merged

allen0099 merged 1 commit into
masterfrom
fix/session-clear-inactive

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Closes #165

Problem

  • clear_expired_sessions() only checked expires_at. A record already marked INVALIDATED (by invalidate_session()) or EXPIRED (by an expired read) is unusable, yet it stayed in the backend until its TTL ran out. Repro: create a session, invalidate it, then call clear_expired_sessions(). It returns 0 and the key remains.
  • clear_expired_sessions() and delete_user_sessions() sent one sequential delete per session.

Fix

  • clear_expired_sessions() now removes any session whose status is not ACTIVE, as well as any session past expires_at.
  • Both sweeps collect the matching keys and remove them with a single backend.delete_many() call. The returned count comes from delete_many. On memory and Redis, that is what was actually removed. On the base fallback, it is what was attempted.
  • docs/SESSION.md and zh-TW describe what clear_expired_sessions() removes and the single batch delete.

Tests

  • test_clear_expired_sessions_removes_sessions_no_longer_active[invalidated|expired]
  • test_session_sweeps_delete_in_one_batch: each sweep makes exactly one delete_many call with the right number of keys, and no per-key delete calls.
  • Mutation check: with the manager.py change reverted, exactly these 3 tests fail (208 others pass).
  • ruff, mypy --strict, and the full suite against live Redis and Memcached (CACHEX_REQUIRE_LIVE_SERVERS=1): 864 passed.

CHANGELOG entry

Section: Fixed (added to CHANGELOG.md via #206)

- **`clear_expired_sessions()` also removes invalidated and expired-status
  sessions.** It only checked `expires_at`, so a session marked `INVALIDATED`
  by `invalidate_session()` or `EXPIRED` by an expired read stayed in the
  backend until its TTL ran out. Any session that is no longer `ACTIVE` is now
  removed. `clear_expired_sessions()` and `delete_user_sessions()` also delete
  what they find with one `backend.delete_many()` call instead of one `delete`
  per session.
  ([#165](https://github.com/allen0099/FastAPI-CacheX/issues/165))

clear_expired_sessions() only looked at expires_at, so records already
marked INVALIDATED (invalidate_session) or EXPIRED (an expired read)
stayed in the backend until their TTL ran out. Treat any record that is
no longer ACTIVE as removable too.

Both clear_expired_sessions() and delete_user_sessions() now collect the
matching keys and remove them with one backend.delete_many() call instead
of one sequential delete per session; the count comes from delete_many.

Closes #165
@allen0099 allen0099 added this to the 0.3.8 milestone Sep 26, 2026
@allen0099 allen0099 added bug Something isn't working session Session management subsystem labels Sep 26, 2026
@allen0099
allen0099 merged commit 0b5b4d4 into master Sep 26, 2026
11 checks passed
@allen0099
allen0099 deleted the fix/session-clear-inactive branch September 26, 2026 14:35
allen0099 added a commit that referenced this pull request Sep 27, 2026
Copies the CHANGELOG sections of #207, #208, #209, #211, #212, #272,
#273, #274, #275, #276, #279 and #284 into Unreleased. The #273 entry
drops expire_if_equals from its list of methods that changed, since that
primitive is new in 0.3.8.
allen0099 added a commit that referenced this pull request Sep 27, 2026
Copies the CHANGELOG sections of #207, #208, #209, #211, #212, #272,
#273, #274, #275, #276, #279 and #284 into Unreleased. The #273 entry
drops expire_if_equals from its list of methods that changed, since that
primitive is new in 0.3.8.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working session Session management subsystem

Projects

None yet

Development

Successfully merging this pull request may close these issues.

clear_expired_sessions() skips expired and invalidated records; batch the deletes

1 participant