Skip to content

fix(session): an anonymous request stores no session - #200

Merged
tina4stack merged 1 commit into
tina4stack:v3from
MichaelC8E:fix/an-anonymous-request-stores-no-session
Oct 5, 2026
Merged

tina4stack merged 1 commit into
tina4stack:v3from
MichaelC8E:fix/an-anonymous-request-stores-no-session

Conversation

@MichaelC8E

Copy link
Copy Markdown
Contributor

Every request, including static files, 404s and health checks, stored a session or set a session cookie even when nothing was ever put in it, so session storage grew with anonymous traffic.

Change. A session that was never stored and holds no data of its own is no longer written and gets no cookie. That also covers a request that only marked the session changed without leaving anything in it (deleting a key it never had, clear(), regenerate() on an empty session): a record with no data is not a session. A request that stores a value, or that arrived with a session cookie for a stored session, behaves as before, and clearing a stored session still ends it.

python: Session.is_fresh() looks at the raw data, so a session holding only SSO pending state is not fresh. The cookie decision is _session_needs_cookie().

Tests. tests/test_session_anonymous_request.py (19 tests) runs real requests, including a request that carries an unknown cookie and the logout case, and fails on v3 3.13.147 without this change.

Every request, including static files, 404s and health checks, stored
a session or set a session cookie even when nothing was ever put in
it, so session storage grew with anonymous traffic.

A session that was never stored and holds no data of its own is no
longer written and gets no cookie. That also covers a request that
only marked the session changed without leaving anything in it
(deleting a key it never had, clear(), regenerate() on an empty
session): a record with no data is not a session. A request that
stores a value, or that arrived with a session cookie for a stored
session, behaves as before, and clearing a stored session still ends
it.

python: Session.is_fresh() looks at the raw data, so a session holding
only SSO pending state is not fresh. The cookie decision is
_session_needs_cookie().

Signed-off-by: Michael <[email protected]>
@MichaelC8E

Copy link
Copy Markdown
Contributor Author

I have read the Tina4 Contributor Licence Agreement and I agree to it.

@tina4stack
tina4stack merged commit d9467a0 into tina4stack:v3 Oct 5, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants