Repository navigation
test(session): exercise the deprecated SessionMiddleware over HTTP - #283
Merged
Merged
Conversation
Install it with add_middleware and observe the loaded session through get_optional_session and the response headers instead of calling _extract_token, _get_client_ip and dispatch on a hand-built instance. Several old tests built the middleware without installing it, so their requests never reached it. The DeprecationWarning is now expected with pytest.warns; tests that only use the middleware as scaffolding filter that one warning. The client IP cases call the public get_client_ip instead of the private method.
allen0099
force-pushed
the
test/deprecated-session-middleware-188
branch
from
September 27, 2026 10:28
69ecb98 to
a0c7c24
Compare
This was referenced Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #188
Part of #123.
tests/session/test_middleware.pynow tests the deprecatedSessionMiddlewarethe way an app uses it:app.add_middleware;TestClient;get_optional_sessionand the response headers.The tests no longer call
_extract_token,_get_client_ipordispatchon a hand-built instance.Several old "dispatch" tests constructed
SessionMiddleware(app, ...)without installing it. Their requests never reached the middleware, and they only assertedstatus_code == 200.The
DeprecationWarningis now expected explicitly:_client()helper wraps the warm-up request inpytest.warns. Starlette builds the middleware stack on that first request.FastAPICacheXSessionMiddleware.test_get_session_manager.pyandtest_dependencies.pyuse the deprecated middleware only as scaffolding. They get a targetedfilterwarnings("ignore:SessionMiddleware is deprecated:DeprecationWarning"). Their fixtures are untouched, to keep the conflict with Tests: move shared session fixtures to tests/session/conftest.py #187 small.What replaces what
test_middleware_initialization(middleware.config is config)test_an_explicit_config_overrides_the_managers: the override's header is read, the default header is nottest_middleware_initialization_uses_manager_configtest_config_defaults_to_the_managers: a custom header on the manager's config is honouredtest_the_manager_defaults_to_the_proxy:session_manager=Nonefalls back toSessionManagerProxytest_extract_token_from_header,test_dispatch_sets_session_in_request_state,test_dispatch_direct_calltest_a_header_token_loads_the_session: session ID and user, and no token header in the responsetest_extract_token_from_bearertest_a_bearer_token_loads_the_sessiontest_extract_token_none,test_extract_token_from_bearer_with_malformed_header,test_dispatch_with_invalid_session,test_dispatch_with_no_session,test_dispatch_with_session_errortest_a_missing_or_invalid_token_loads_no_session: no token, invalid header token, empty and invalid Bearertest_dispatch_with_expired_sessiontest_an_expired_session_is_not_loaded: now asserts the session is absenttest_dispatch_with_session_and_ip_bindingtest_ip_binding_checks_the_peer_address: match loads, mismatch does nottest_get_client_ip_*viamiddleware._get_client_ipget_client_ip, plustest_ip_binding_uses_the_forwarded_address_behind_a_trusted_proxyend to endtest_dispatch_with_user_agent_bindingtest_user_agent_binding_checks_the_request_user_agent: match and mismatchtest_a_rotated_session_id_is_sent_back_as_a_new_token:rotate_session_idgives a new header token, and the old one no longer resolvestest_dispatch_sets_renewed_token_header_on_sliding_expirationtest_sliding_expiration_sends_the_renewed_token(same assertions, via the helper)The
_extract_header_tokenfallback-chain tests at the bottom of the file are unchanged. Their_connectionhelper gained an optionalpeer.Tests
uv run pytest tests/session/test_middleware.py -W error::DeprecationWarning: 40 passed, on Python 3.10 and 3.14.uv run pytest tests/session -W error::DeprecationWarning: 248 passed. Before this PR, 28 tests failed under that flag.fastapi_cachex/session/middleware.pyfromtest_middleware.pyalone went from 53% to 54%. TheSessionMiddlewareclass is now fully covered by this file; before, the no-token branch (231->247) and the regenerated-ID branch (257) were missed.middleware.pystays at 99% (the one partial is473->exit, in the other middleware). Total stays at 94%. The run now emits 6 warnings instead of 34; the remaining ones are the JWT short-key warnings, which are for Tests: tighten the pytest configuration #189.dispatchfailstest_a_rotated_session_id_is_sent_back_as_a_new_tokenand the two existingtest_deprecated_middleware_sends_regenerated_tokencases.trusted_proxies, fails onlytest_ip_binding_uses_the_forwarded_address_behind_a_trusted_proxy[203.0.113.7-True].configto a freshSessionConfiginstead of the manager's fails onlytest_config_defaults_to_the_managers.ruff checkandruff formatare clean; pre-commit passed on commit.CHANGELOG
None: test-only.