Skip to content

fix(cache): send private to credentialed requests on cache_authorized routes - #373

Merged
allen0099 merged 1 commit into
masterfrom
fix/372-cache-authorized-private
Sep 29, 2026
Merged

allen0099 merged 1 commit into
masterfrom
fix/372-cache-authorized-private

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Fixes #372

Summary

  • @cache(cache_authorized=True) still reads and writes the backend for requests with Authorization or a session, but every answer to them (miss, hit, 304) now carries private in place of public, with the decorator's other directives kept. The per-caller key only exists in this backend; a CDN in front of the app keys on the URL alone.
  • get_session / get_optional_session (and the dependencies built on them) flag the request as having read the session, so FastAPICacheXSessionMiddleware and the deprecated SessionMiddleware add Vary for the token sources, the same as a request.session access.
  • Docs (EN + zh-TW): HTTP_CACHING, CACHE_FLOW, SESSION. The authenticated-endpoint example no longer sets Vary: Authorization by hand.
  • Changelog: new 372.security.md; 362.security.md no longer lists cache_authorized as exempt from private.

Tests

  • New tests/session/test_cache_authorized_private.py, with two existing expectations updated.
  • Mutation checks: reverting cache.py fails 7 tests, dropping the dependency flag fails 4, and dropping the deprecated middleware change fails 1.
  • Full suite passes (coverage 94.55%), pre-commit passes, and both docs builds pass with --strict.

… routes

cache_authorized=True keys the backend entry on the caller, but its
responses kept the decorator's Cache-Control, which a shared cache keyed
on the URL may store and replay to other users. They now carry private,
like the bypassed ones. Session dependencies also mark the request as
having read the session, so the session middlewares add Vary for the
token sources as they do for request.session.

Fixes #372
@allen0099 allen0099 added this to the 0.3.9 milestone Sep 29, 2026
@allen0099 allen0099 added http-cache The @cache decorator, cache keys and Cache-Control handling session Session management subsystem security Security vulnerability or hardening labels Sep 29, 2026
@allen0099
allen0099 merged commit e21fd56 into master Sep 29, 2026
12 checks passed
@allen0099
allen0099 deleted the fix/372-cache-authorized-private branch September 29, 2026 09:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

http-cache The @cache decorator, cache keys and Cache-Control handling security Security vulnerability or hardening session Session management subsystem

Projects

None yet

Development

Successfully merging this pull request may close these issues.

@cache(cache_authorized=True) sends no private or Vary, so a shared cache may serve one user's response to another

1 participant