process_response marks the session accessed, so every response gets Vary: Cookie
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 78/100
Hướng nghiên cứu
Start by reproducing the issue with Quart's test client and inspect Quart.process_response, then compare the websocket counterpart where session_ = ctx.session is also used. Update both paths so untouched sessions do not produce Vary: Cookie while session-using requests retain the header; verify both behaviors with regression tests.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Quart.process_response reads the session through the ctx.session property:
session_ = ctx.session
if not self.session_interface.is_null_session(session_):
await self.ensure_async(self.session_interface.save_session)(
self, session_, response
)
That property sets session.accessed = True, so SecureCookieSessionInterface.save_session then adds Vary: Cookie to every response. This includes views that never touch the session, and static files. As a result, no shared cache or CDN will store them.
Minimal reproduction (Quart 0.23.1, also current main):
import asyncio
from quart import Quart
app = Quart(__name__)
app.secret_key = "not-secret"
@app.get("/")
async def index() -> str:
return "this view never touches the session"
async def main() -> None:
response = await app.test_client().get("/")
print("Vary:", response.headers.get("Vary"))
asyncio.run(main())
Output: Vary: Cookie. The equivalent Flask 3.1.3 app prints Vary: None, because Flask's process_response reads the private attribute instead:
if not self.session_interface.is_null_session(ctx._session):
self.session_interface.save_session(self, ctx._session, response)
Proposed fix: do the same in Quart.process_response (and in the websocket counterpart, which has the same session_ = ctx.session line), so only a request that actually used the session varies on the cookie. I'm happy to open a PR.
- Ngôn ngữ chính
- Python
- Star
- 3.7k
- Fork
- 206
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của pallets/quart
-
Changelog link is brokenĐang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 68/100
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 42/100
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
Tất cả issue của pallets/quart
Issue tương tự
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 72/100
letsencrypt/cp-cps#353 ·
-
Marble Madness II is missingĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
PedestrianDynamics/pyFDS-Evac#394 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
DOI-USGS/pywatershed#421 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
python-pillow/Pillow#10087 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày