Repository navigation
feat(cache): warn once when a credential makes a route bypass the backend - #350
Merged
Merged
Conversation
…kend The Authorization and session bypass was logged only at DEBUG, so a route that never hit the cache gave no sign of why. The first bypass per route and credential kind is now logged at WARNING, naming the route template and the credential kind and pointing to public=True or cache_authorized=True with a per-user key_builder. Documents the choice in HTTP_CACHING.md (en, zh-TW). Closes #326
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A request with
Authorizationor a session bypasses the shared backend on a plain@cacheroute. Until now each bypass was logged only atDEBUG, so a route with no cache hits gave no sign of why. That affects SPAs that sendAuthorizationon every request and, since #338, every request that carries a session.WARNINGonfastapi_cachex.cache. The message names the route template and the credential (an Authorization header / a session token / non-empty session data). It points topublic=Truefor a response that is the same for every user, noting that this also sendsCache-Control: publicdownstream, and tocache_authorized=Truewith a per-userkey_builderfor a per-user response. The per-requestDEBUGlog is unchanged._BypassWarner. Inside it, a set is keyed by(route template, credential kind), so one handler registered on two routes warns for each, and every test's fresh app starts with no state. The key is the route template (scope["route"].path), never the requested path. That keeps the set bounded, keeps client-chosen paths out of the log, and means/items/1and/items/2share one warning. Without a matched route, the handler's qualified name is used.threading.Lockmakes "once" exact. The lock is taken only on a bypass whose pair has not been recorded yet: an unlocked membership check returns early once it has.%r) and the credential kind, never a header value or token.docs/HTTP_CACHING.mdexplains which option to choose and describes the warning. It is mirrored ini18n/zh-TW/docs/HTTP_CACHING.md.changelog.d/326.added.md.Tests
tests/session/test_cache_bypass_warning.pycovers:request.sessiondata): exactly oneWARNINGacross three requests, threeDEBUGlines, and no token in any log line.public=Trueandcache_authorized=Trueroutes, credential-less requests andprivate=Trueroutes do not warn.Mutation checks. Each one fails at least one test:
publicroutes.Closes #326