Skip to content

fix: warn instead of using a placeholder key in the session examples, and clarify warnings and clear() docs - #397

Merged
allen0099 merged 1 commit into
masterfrom
fix/384-386-first-use
Sep 29, 2026
Merged

allen0099 merged 1 commit into
masterfrom
fix/384-386-first-use

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Fixes #384. Fixes #385. Fixes #386.

Three findings from a first-use run of the current release, fixed before 0.3.9.

#384: session examples

  • The five session examples no longer fall back to a fixed placeholder key.
  • A session_secret_key() helper returns SESSION_SECRET_KEY when it is set. Otherwise it emits a UserWarning and returns a random key for that run.
  • examples/README.md "Secrets" is updated.
  • In tests/test_examples.py, an autouse fixture sets the variable. A parametrized test checks the warning, that it points at the example file, and that each run gets a new key.

#385: docs (EN and zh-TW)

  • BACKENDS.md and APP_CACHE.md now separate MemcachedBackend.clear() (flush_all, wipes the whole server) from CacheManager.clear() (deletes nothing on Memcached). The APP_CACHE note warns against falling back to the backend's clear().
  • The Redis section notes that clear(), clear_pattern() and clear_path() are scoped to key_prefix.

#386: warnings

  • get_session_manager()'s FutureWarning now says whether SessionManagerProxy is empty or holds a different manager.
  • The __Host-/__Secure- cookie-name UserWarning links 0.4.0: explicit login()/logout() that always rotate the session ID, and __Host- cookie by default #256.
  • The Memcached RuntimeWarnings of clear(), clear_path(), clear_pattern() and get_all_keys() use _caller_stacklevel(). It names the first frame outside fastapi_cachex, so a call through CacheManager points at the application instead of manager.py.
  • get_cache_data() keeps stacklevel=2: only the monitoring route calls it, and its caller is FastAPI itself.
  • The new CacheManager attribution test fails on the previous code.

Changelog fragments: 384.security.md and 386.fixed.md. #385 is docs only.

Checks: pre-commit, mypy strict, the full suite including the Redis and Memcached suites (1519 passed, coverage 99%), and both strict docs builds.

… and clarify warnings and clear() docs

- Session examples warn when SESSION_SECRET_KEY is unset and sign with a
  random key for that run instead of a published placeholder (#384).
- Docs separate MemcachedBackend.clear() (flush_all) from
  CacheManager.clear() (no-op on Memcached) and note that Redis clears
  are prefix-scoped (#385).
- get_session_manager()'s FutureWarning tells an empty proxy from a
  different manager, the cookie-prefix UserWarning links #256, and the
  Memcached RuntimeWarnings name the first frame outside the library (#386).
@allen0099 allen0099 added this to the 0.3.9 milestone Sep 29, 2026
@allen0099 allen0099 added bug Something isn't working session Session management subsystem labels Sep 29, 2026
@allen0099
allen0099 merged commit 50131d7 into master Sep 29, 2026
14 checks passed
@allen0099
allen0099 deleted the fix/384-386-first-use branch September 29, 2026 14:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working session Session management subsystem

Projects

None yet

1 participant