AllenNeuralDynamics / AllenNeuralDynamics/aind-data-transfer-service

Add session `max_age` to SessionMiddleware

Offen
#267 1 Kommentar 0 Reaktionen 1 zugewiesene Person Beansprucht von @yosefmaru Auf GitHub ansehen
Vorherrschende Sprache
Python
Sterne
3
Forks
0
Ø Merge
11 Min.
Gemergte PRs (30 T.)
1

Beschreibung

**Is your feature request related to a problem? Please describe.**
Currently, when the user logs in, their `userinfo` (not full token) is saved in the request session. This is saved until the user logs out, or the browser session is cleared, or the default session `max_age` of 2 weeks.

**Describe the solution you'd like**
The request session should have a shorter `max_age`. Consider having it match the auth token timeout?

**Describe alternatives you've considered**
Save and refresh the auth token if it has expired.

**Additional context**
See https://www.starlette.io/middleware/#sessionmiddleware:
> max_age - Session expiry time in seconds. Defaults to 2 weeks. If set to None then the cookie will last as long as the browser session.

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.