Skip to content

fix(session): warn when cookie_same_site="none" lacks cookie_https_only - #217

Merged
allen0099 merged 1 commit into
masterfrom
fix/session-samesite-none-warning
Sep 26, 2026
Merged

allen0099 merged 1 commit into
masterfrom
fix/session-samesite-none-warning

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Closes #167 (part of #117)

Problem

Browsers reject a SameSite=None cookie that is not Secure. With cookie_same_site="none" and the default cookie_https_only=False, FastAPICacheXSessionMiddleware sends a cookie that the client silently drops, so the session never sticks and nothing tells the developer why.

Change

  • SessionConfig has a model_validator(mode="after") that emits a UserWarning for this combination. stacklevel points at the line that builds the config.
  • The combination is still accepted. Rejecting it would break existing configurations; that can be decided for 0.4.0.
  • Docs (en and zh-TW SESSION.md): the cookie_same_site comment in the configuration example notes that "none" needs cookie_https_only=True.
  • CHANGELOG: a Fixed entry.

Tests

In tests/session/test_config.py:

  • test_same_site_none_without_https_only_warns
  • test_other_cookie_settings_do_not_warn, for none+True, lax+False and strict+False, with warnings turned into errors.

Mutation checks:

  • dropping the cookie_https_only condition fails only the none-True case;
  • disabling the warning fails only the warns test.

Ruff, mypy --strict, the full suite against live Redis and Memcached (897 passed), and zensical build --strict for both languages.

Browsers reject a SameSite=None cookie without the Secure flag, so this
configuration silently never stored the session cookie. SessionConfig
now emits a UserWarning at validation time. The combination is still
accepted; rejecting it would break existing configurations.

Closes #167
@allen0099 allen0099 added this to the 0.3.8 milestone Sep 26, 2026
@allen0099 allen0099 added enhancement New feature or request session Session management subsystem labels Sep 26, 2026
@allen0099
allen0099 merged commit feac589 into master Sep 26, 2026
11 checks passed
@allen0099
allen0099 deleted the fix/session-samesite-none-warning branch September 26, 2026 16:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request session Session management subsystem

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Warn when cookie_same_site is "none" without cookie_https_only

1 participant