Repository navigation
0.5.0: remove session and OAuth state, lower the dependency floors, migrating from fastapi-cache2 - #450
Open
allen0099 wants to merge 2 commits into
Open
0.5.0: remove session and OAuth state, lower the dependency floors, migrating from fastapi-cache2#450allen0099 wants to merge 2 commits into
allen0099 wants to merge 2 commits into
Conversation
Remove fastapi_cachex.session and fastapi_cachex.state, deprecated in 0.4.0 (#420), with their tests, examples, docs pages, API reference pages and nav entries, the lazy deprecated names on fastapi_cachex and the _deprecation module. The jwt extra and PyJWT go with them. @cache drops the session-middleware special cases: a session loaded by the removed middleware no longer counts as a credential, and X-Session-Token is no longer hashed in vary keys. Authorization and a non-empty request.session from any session middleware still bypass the backend; a Cookie header alone still does not. The bypass tests move to tests/ and use Starlette's SessionMiddleware. BaseCacheBackend's fallbacks read delete()'s result with bool(), so a third-party delete() returning None counts as not removed, without the 0.4.x FutureWarning. Dependencies: itsdangerous and the direct starlette>=1.0.0 requirement are dropped, and the fastapi floor goes from 0.133.0 to 0.128.2, the oldest release the suite passes on with the oldest starlette it accepts (0.40.0, now pinned in the lowest tox env). Add docs/MIGRATING_0_5.md and its zh-TW copy, and changelog fragments. Closes #421
A guide for fastapi-cache2 users: a route before and after, a mapping of FastAPICache.init, @cache(expire, namespace, key_builder, coder), the backends and FastAPICache.clear onto this package, the behaviour that differs (keys from the request, credentialed requests bypass the cache, the client's Cache-Control is ignored, no pickle) and what has no equivalent. Linked from the comparison page, both navs, the README and the zh-TW index. Closes #423
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #421
Fixes #423
Warning
Do not merge until 0.4.x is finished.
release.ymlreleases only frommaster, so merging this ends 0.4.x patch releases. The pending 0.4.2 fragments (#242, #248, #252, #253, #334, #335) would then ship in 0.5.0 instead.Summary
#421: remove session and OAuth state (
feat!commit)fastapi_cachex.sessionandfastapi_cachex.state, deprecated in 0.4.0 (Deprecate fastapi_cachex.session and fastapi_cachex.state; remove them in 0.5.0 #420). This includes their tests, examples, docs pages (en and zh-TW), API reference pages, nav entries, the lazy deprecated names,_deprecation.py, and thejwtextra / PyJWT. Removed names now raiseAttributeError/ModuleNotFoundError.@cache: onlyAuthorizationand a non-emptyrequest.sessionfrom any session middleware still bypass the shared backend. A plainCookieheader still does not bypass, the same as today. The bypass tests moved totests/and now use Starlette'sSessionMiddleware.itsdangerousand the directstarlette>=1.0.0requirement are dropped.fastapifloor goes from0.133.0to0.128.2, found by bisecting withtox -e lowest:Responsetests.lowestenv now pinsstarlette>=0.40.0, the oldest version that fastapi 0.128.2 accepts.itsdangerousmoved to the dev group, for theSessionMiddlewaretests.BaseCacheBackend's fallbacks readdelete()withbool(). A third-partydelete()that returnsNonenow counts as not removed, with noFutureWarning.docs/MIGRATING_0_5.mdand its zh-TW copy, with nav entries.421.removed.md,421.removed.2.md,421.changed.md,421.changed.2.md.#423: migrating from fastapi-cache2 (
docscommit)New
docs/MIGRATING_FROM_FASTAPI_CACHE2.mdand its zh-TW copy. It covers:FastAPICache.init,@cache(expire, namespace, key_builder, coder), the backends,FastAPICache.clear,X-FastAPI-Cache,enableCache-Controlis ignored, and storage is the rendered response with no pickleIt is linked from the comparison page, both navs, the README and the zh-TW index. The fastapi-cache2 facts come from the source of 0.2.2.
For review
X-Session-Tokeninvary=. As the issue asks, it is no longer hashed and is keyed on its raw value, like any other custom header. Hashing it cost nothing and kept tokens out of keys, so keeping that special case is an option if you prefer it.Checklist
tests/cover the change. Each new test fails when the code it guards is broken.uv run pre-commit run --all-filesanduv run pytestpass:mypy testsandmypy scripts: cleantox -e lowest: passeszensical build --strictruns: clean