fix: warn instead of using a placeholder key in the session examples, and clarify warnings and clear() docs - #397
Merged
Merged
Conversation
… and clarify warnings and clear() docs - Session examples warn when SESSION_SECRET_KEY is unset and sign with a random key for that run instead of a published placeholder (#384). - Docs separate MemcachedBackend.clear() (flush_all) from CacheManager.clear() (no-op on Memcached) and note that Redis clears are prefix-scoped (#385). - get_session_manager()'s FutureWarning tells an empty proxy from a different manager, the cookie-prefix UserWarning links #256, and the Memcached RuntimeWarnings name the first frame outside the library (#386).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #384. Fixes #385. Fixes #386.
Three findings from a first-use run of the current release, fixed before 0.3.9.
#384: session examples
session_secret_key()helper returnsSESSION_SECRET_KEYwhen it is set. Otherwise it emits aUserWarningand returns a random key for that run.examples/README.md"Secrets" is updated.tests/test_examples.py, an autouse fixture sets the variable. A parametrized test checks the warning, that it points at the example file, and that each run gets a new key.#385: docs (EN and zh-TW)
MemcachedBackend.clear()(flush_all, wipes the whole server) fromCacheManager.clear()(deletes nothing on Memcached). The APP_CACHE note warns against falling back to the backend'sclear().clear(),clear_pattern()andclear_path()are scoped tokey_prefix.#386: warnings
get_session_manager()'sFutureWarningnow says whetherSessionManagerProxyis empty or holds a different manager.__Host-/__Secure-cookie-nameUserWarninglinks 0.4.0: explicit login()/logout() that always rotate the session ID, and __Host- cookie by default #256.RuntimeWarnings ofclear(),clear_path(),clear_pattern()andget_all_keys()use_caller_stacklevel(). It names the first frame outsidefastapi_cachex, so a call throughCacheManagerpoints at the application instead ofmanager.py.get_cache_data()keepsstacklevel=2: only the monitoring route calls it, and its caller is FastAPI itself.Changelog fragments:
384.security.mdand386.fixed.md. #385 is docs only.Checks: pre-commit, mypy strict, the full suite including the Redis and Memcached suites (1519 passed, coverage 99%), and both strict docs builds.