Repository navigation
feat: deprecate session and OAuth state, to be removed in 0.5.0 - #426
Merged
Merged
Conversation
Importing fastapi_cachex.session or fastapi_cachex.state, or reading one of their names from the package, emits a FutureWarning that points at the importing line. A plain `import fastapi_cachex` no longer imports either package: the top-level names load lazily and leave __all__, and @cache inlines the X-Session-Token header name instead of importing it. The migration guide, the session/state/JWT pages (English and zh-TW), the README, the examples index and SECURITY.md say where to move.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #420.
fastapi_cachex.sessionandfastapi_cachex.stateare deprecated in 0.4.0 and will be removed in 0.5.0 (#421). The package narrows to HTTP and application caching.What changes
fastapi_cachex.sessionorfastapi_cachex.state, or reading one of their names fromfastapi_cachex, emits aFutureWarningonce per process. The warning points at the application's own line, not at a frame inside the package or the import machinery, and links to the new migration section.import fastapi_cachexstays silent. The top-level session/state names are resolved lazily through a module__getattr__, are no longer in__all__, and are still visible to type checkers through aTYPE_CHECKINGblock.cache.pyno longer importssession.config.get_session_managerthroughSessionManagerProxy#131:get_session_managerno longer warns about the proxy fallback.token_source_priorityomits"cookie".use_bearer_tokenstays deprecated and is now removed in 0.5.0 along with the package.MIGRATING_0_4.mdhas a new "Sessions and OAuth state are deprecated" section with alternatives (StarletteSessionMiddleware/ starsessions, Authlib, auth-stack tokens). The session, state and JWT pages get a deprecation banner, and the nav, README and site description are updated. The zh-TW translation follows.SECURITY.md: session and state receive security fixes only during 0.4.x.changelog.d/420.deprecated.md.Tests
tests/test_session_state_deprecation.pyruns each import style in a subprocess and asserts the warning's file and line. It also checks that every core module imports without aFutureWarning, thatstatedoes not importsession, and that theTYPE_CHECKINGimports match the lazy-name table.tests/session/test_dropped_0_4_0_changes.pyasserts the dropped notices stay silent.examples/run as before. The warnings themselves are covered by the subprocess tests, not bytest_examples.TYPE_CHECKINGline, or restoring the old notices each makes the guarding tests fail.An independent review agent reviewed the change before this PR. Its findings are addressed in the second commit.