fix(stage-326): preserve SESSION_TTL constant + reconcile #1957 tests
PR #1957 deleted the SESSION_TTL = 86400 * 30 module-level constant in favor of the new _resolve_session_ttl() helper. Two existing regression tests pin the constant: test_auth_sessions.TestSessionPruning.test_session_ttl_is_24_hours imports SESSION_TTL directly, and test_v050258_opus_followups.test_redirect_session_ttl_30_days asserts the literal "SESSION_TTL = 86400 * 30" line is present in source (guarding against the daily-kick-out regression from #1419). Restore SESSION_TTL as the named fallback for _resolve_session_ttl(); the new env-var/settings.json path is unchanged. Backwards-compatible. Also fix the new TestSessionTtlResolution suite: - Switch from pytest's `monkeypatch` fixture (incompatible with unittest.TestCase subclasses) to setUp/tearDown env snapshotting - Reconcile clamp tests with actual implementation: out-of-range env values fall through to settings/default, not snap to bounds - test_session_uses_dynamic_ttl now sets the env var so the dynamic resolved value (3600s) is exercised rather than expecting the default Verified: tests/test_auth_sessions.py + tests/test_v050258_opus_followups.py 21/21 pass.
This commit is contained in:
13
api/auth.py
13
api/auth.py
@@ -18,12 +18,19 @@ from api.config import STATE_DIR, load_settings
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
# Default session TTL — 30 days. Kept as a module-level constant for backwards
|
||||
# compatibility with downstream code and regression tests that import it.
|
||||
# At runtime, prefer ``_resolve_session_ttl()`` which honours the env var and
|
||||
# settings.json overrides; this constant is the floor / fallback.
|
||||
SESSION_TTL = 86400 * 30 # 30 days
|
||||
|
||||
|
||||
def _resolve_session_ttl() -> int:
|
||||
"""Resolve session TTL from env > settings > default.
|
||||
|
||||
Priority mirrors get_password_hash(): HERMES_WEBUI_SESSION_TTL env var
|
||||
first, then settings.json, falling back to 30 days. Clamped to
|
||||
[60s, 1 year] to prevent runaway cookies or self-lockout.
|
||||
first, then settings.json, falling back to ``SESSION_TTL`` (30 days).
|
||||
Clamped to [60s, 1 year] to prevent runaway cookies or self-lockout.
|
||||
"""
|
||||
env_v = os.getenv('HERMES_WEBUI_SESSION_TTL', '').strip()
|
||||
if env_v.isdigit():
|
||||
@@ -34,7 +41,7 @@ def _resolve_session_ttl() -> int:
|
||||
v = s.get('session_ttl_seconds')
|
||||
if isinstance(v, int) and 60 <= v <= 86400 * 365:
|
||||
return v
|
||||
return 86400 * 30 # current default (30 days)
|
||||
return SESSION_TTL
|
||||
|
||||
|
||||
# ── Public paths (no auth required) ─────────────────────────────────────────
|
||||
|
||||
Reference in New Issue
Block a user