feat(session)!: add logout() and login(keep=), make Session.user read-only - #416
Merged
Merged
Conversation
…-only `await logout(request)` deletes the session from the backend at once, so its token stops resolving before the response is sent, and the middleware expires a cookie client's cookie. It returns False when no session was loaded or started in the request. `login(request, user, keep=[...])` carries only the listed keys of the session the request arrived with over to the logged-in one, both from the stored record and from what the handler wrote before the call. A string is rejected with TypeError. Assigning `Session.user` raises AttributeError, so a session gets a user only when it is built, from `login()` (which rotates the ID) or from `SessionManager.create_session(user=...)`. BREAKING CHANGE: assigning `Session.user` raises AttributeError. Under FastAPICacheXSessionMiddleware use `login(request, user)`; without it, create the session with `SessionManager.create_session(user=...)`. Closes #256
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #256. This is the rest of the proposal after #415 (cookie defaults):
logout(),login(keep=)and a read-onlySession.user.Changes
await logout(request)(fastapi_cachex.session):request.session.clear()path, so the middleware expires a cookie client's cookie;get_sessionfinds no session, keys written afterwards start a new anonymous session, and a laterlogin()starts a new session;True, orFalsewhen no session was loaded or started in the request;RuntimeErrorwithoutFastAPICacheXSessionMiddleware.login(request, user, *, keep=...):request.sessionbefore the call;keep=[]carries nothing; keys written after the call are kept;keeplists;strraisesTypeError(keep="cart"would otherwise mean its letters).Session.useris read-only: assigning it raisesAttributeError, with a message that points tologin()/create_session(user=...).model_validateandmodel_copystill accept a user;login()uses a private_attach_user().__setattr__override is hidden from type checkers, so typos such assession.dta = ...are still reported.examples/session_login.pylogs out withlogout().SESSION.md: read-onlyuser,logout(),keep=, and howlogout()differs fromclear().MIGRATING_0_4.md#login-logout: rewritten for the implemented behaviour.256.added.md(logout(),keep=) and256.changed.2.md(read-onlySession.user).No 0.3.9 warning for the read-only
user: 0.3.x cannot tell which code assigns it, as the migration guide already says.Tests
tests/session/test_logout_and_keep.py(19 tests):logout()over the cookie, header and bearer transports; without a session; writes after it;login()after it;login()thenlogout(); outside the middleware;keep=on an anonymous session, a re-login, a new visitor and another user's session, and a string argument;userraises, other fields stay assignable, a user can still be given when aSessionis built.test_session_loginchecks the example's/logoutreturn values.__setattr__guard;request.sessionfilter or the stored-record filter;logout();request.sessionfor another user's session.mypy --strict,mypy tests/scripts, both strict docs builds andtox -e lowestpass.