Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

process_response marks the session accessed, so every response gets Vary: Cookie

Đang mở
#480 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
78/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
python
Lĩnh vực
backend

Hướng nghiên cứu

Start by reproducing the issue with Quart's test client and inspect Quart.process_response, then compare the websocket counterpart where session_ = ctx.session is also used. Update both paths so untouched sessions do not produce Vary: Cookie while session-using requests retain the header; verify both behaviors with regression tests.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Quart.process_response reads the session through the ctx.session property:

session_ = ctx.session
if not self.session_interface.is_null_session(session_):
    await self.ensure_async(self.session_interface.save_session)(
        self, session_, response
    )

That property sets session.accessed = True, so SecureCookieSessionInterface.save_session then adds Vary: Cookie to every response. This includes views that never touch the session, and static files. As a result, no shared cache or CDN will store them.

Minimal reproduction (Quart 0.23.1, also current main):

import asyncio

from quart import Quart

app = Quart(__name__)
app.secret_key = "not-secret"


@app.get("/")
async def index() -> str:
    return "this view never touches the session"


async def main() -> None:
    response = await app.test_client().get("/")
    print("Vary:", response.headers.get("Vary"))


asyncio.run(main())

Output: Vary: Cookie. The equivalent Flask 3.1.3 app prints Vary: None, because Flask's process_response reads the private attribute instead:

if not self.session_interface.is_null_session(ctx._session):
    self.session_interface.save_session(self, ctx._session, response)

Proposed fix: do the same in Quart.process_response (and in the websocket counterpart, which has the same session_ = ctx.session line), so only a request that actually used the session varies on the cookie. I'm happy to open a PR.

Ngôn ngữ chính
Python
Star
3.7k
Fork
206
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của pallets/quart

Tất cả issue của pallets/quart

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.