Skip to content

feat(session)!: make UserSessionDep require a session with a user - #403

Merged
allen0099 merged 1 commit into
masterfrom
remove/127-user-session-dep
Sep 29, 2026
Merged

allen0099 merged 1 commit into
masterfrom
remove/127-user-session-dep

Conversation

@allen0099

Copy link
Copy Markdown
Owner

Fixes #127.

UserSessionDep was an alias of SessionDep, so it also accepted anonymous sessions. It is now Annotated[Session, Depends(require_user_session)], the same as AuthenticatedSession: an anonymous session gets 401.

  • test_require_user_session_rejects_anonymous_sessions is parametrized over AuthenticatedSession and UserSessionDep. The UserSessionDep case fails with the old alias.
  • SESSION.md is updated in EN and zh-TW. No example or snippet uses UserSessionDep on a route meant for anonymous sessions.

Migration: a route that should keep accepting anonymous sessions uses SessionDep.

Checks

  • pre-commit, mypy strict, and the full suite including the Redis and Memcached suites (1515 passed, coverage 99%).
  • An independent review found no blocking issues.

Changelog: changelog.d/127.changed.md.

UserSessionDep was Depends(get_session) and admitted anonymous sessions
despite its name. Resolve it through require_user_session, like
AuthenticatedSession, so an anonymous session gets 401. Parametrize the
anonymous-session test over both annotations and update the session
docs, which described it as an alias until 0.4.0.

BREAKING CHANGE: UserSessionDep requires a user; routes that should
admit anonymous sessions use SessionDep.
@allen0099 allen0099 added this to the 0.4.0 milestone Sep 29, 2026
@allen0099 allen0099 added session Session management subsystem breaking-change Changes public behaviour or API; needs a minor/major release labels Sep 29, 2026
@allen0099
allen0099 merged commit 2147de8 into master Sep 29, 2026
15 checks passed
@allen0099
allen0099 deleted the remove/127-user-session-dep branch September 29, 2026 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

breaking-change Changes public behaviour or API; needs a minor/major release session Session management subsystem

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0.4.0: make UserSessionDep require a session with a user

1 participant