Skip to content

test(session): exercise the deprecated SessionMiddleware over HTTP - #283

Merged
allen0099 merged 1 commit into
masterfrom
test/deprecated-session-middleware-188
Sep 27, 2026
Merged

allen0099 merged 1 commit into
masterfrom
test/deprecated-session-middleware-188

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Summary

Closes #188

Part of #123.

tests/session/test_middleware.py now tests the deprecated SessionMiddleware the way an app uses it:

  • it is installed with app.add_middleware;
  • requests go through TestClient;
  • results are read through get_optional_session and the response headers.

The tests no longer call _extract_token, _get_client_ip or dispatch on a hand-built instance.

Several old "dispatch" tests constructed SessionMiddleware(app, ...) without installing it. Their requests never reached the middleware, and they only asserted status_code == 200.

The DeprecationWarning is now expected explicitly:

  • The _client() helper wraps the warm-up request in pytest.warns. Starlette builds the middleware stack on that first request.
  • A dedicated test checks that the message names FastAPICacheXSessionMiddleware.
  • Six tests in test_get_session_manager.py and test_dependencies.py use the deprecated middleware only as scaffolding. They get a targeted filterwarnings("ignore:SessionMiddleware is deprecated:DeprecationWarning"). Their fixtures are untouched, to keep the conflict with Tests: move shared session fixtures to tests/session/conftest.py #187 small.

What replaces what

Old test (private API or not installed) New test
test_middleware_initialization (middleware.config is config) test_an_explicit_config_overrides_the_managers: the override's header is read, the default header is not
test_middleware_initialization_uses_manager_config test_config_defaults_to_the_managers: a custom header on the manager's config is honoured
(none) test_the_manager_defaults_to_the_proxy: session_manager=None falls back to SessionManagerProxy
test_extract_token_from_header, test_dispatch_sets_session_in_request_state, test_dispatch_direct_call test_a_header_token_loads_the_session: session ID and user, and no token header in the response
test_extract_token_from_bearer test_a_bearer_token_loads_the_session
test_extract_token_none, test_extract_token_from_bearer_with_malformed_header, test_dispatch_with_invalid_session, test_dispatch_with_no_session, test_dispatch_with_session_error test_a_missing_or_invalid_token_loads_no_session: no token, invalid header token, empty and invalid Bearer
test_dispatch_with_expired_session test_an_expired_session_is_not_loaded: now asserts the session is absent
test_dispatch_with_session_and_ip_binding test_ip_binding_checks_the_peer_address: match loads, mismatch does not
test_get_client_ip_* via middleware._get_client_ip same cases via the public get_client_ip, plus test_ip_binding_uses_the_forwarded_address_behind_a_trusted_proxy end to end
test_dispatch_with_user_agent_binding test_user_agent_binding_checks_the_request_user_agent: match and mismatch
(none in this file) test_a_rotated_session_id_is_sent_back_as_a_new_token: rotate_session_id gives a new header token, and the old one no longer resolves
test_dispatch_sets_renewed_token_header_on_sliding_expiration test_sliding_expiration_sends_the_renewed_token (same assertions, via the helper)

The _extract_header_token fallback-chain tests at the bottom of the file are unchanged. Their _connection helper gained an optional peer.

Tests

  • uv run pytest tests/session/test_middleware.py -W error::DeprecationWarning: 40 passed, on Python 3.10 and 3.14. uv run pytest tests/session -W error::DeprecationWarning: 248 passed. Before this PR, 28 tests failed under that flag.
  • Coverage of fastapi_cachex/session/middleware.py from test_middleware.py alone went from 53% to 54%. The SessionMiddleware class is now fully covered by this file; before, the no-token branch (231->247) and the regenerated-ID branch (257) were missed.
  • Full suite without live servers: before, 841 passed and 190 skipped; after, 845 passed and 190 skipped. middleware.py stays at 99% (the one partial is 473->exit, in the other middleware). Total stays at 94%. The run now emits 6 warnings instead of 34; the remaining ones are the JWT short-key warnings, which are for Tests: tighten the pytest configuration #189.
  • Mutation checks, each run against the full suite:
    • Dropping the regenerated-ID branch in dispatch fails test_a_rotated_session_id_is_sent_back_as_a_new_token and the two existing test_deprecated_middleware_sends_regenerated_token cases.
    • Resolving the client IP from the peer, ignoring trusted_proxies, fails only test_ip_binding_uses_the_forwarded_address_behind_a_trusted_proxy[203.0.113.7-True].
    • Defaulting config to a fresh SessionConfig instead of the manager's fails only test_config_defaults_to_the_managers.
  • ruff check and ruff format are clean; pre-commit passed on commit.

CHANGELOG

None: test-only.

Install it with add_middleware and observe the loaded session through
get_optional_session and the response headers instead of calling
_extract_token, _get_client_ip and dispatch on a hand-built instance.
Several old tests built the middleware without installing it, so their
requests never reached it.

The DeprecationWarning is now expected with pytest.warns; tests that only
use the middleware as scaffolding filter that one warning. The client IP
cases call the public get_client_ip instead of the private method.
@allen0099
allen0099 force-pushed the test/deprecated-session-middleware-188 branch from 69ecb98 to a0c7c24 Compare September 27, 2026 10:28
@allen0099
allen0099 merged commit 02534eb into master Sep 27, 2026
10 checks passed
@allen0099
allen0099 deleted the test/deprecated-session-middleware-188 branch September 27, 2026 10:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Tests: exercise the deprecated SessionMiddleware through its public API

1 participant