Missing DB sessions create a new session for every request
|Reported by:||nezroy <nezroy@…>||Owned by:||nobody|
|Severity:||Keywords:||session invalid stale duplicate clutter|
|Has patch:||yes||Needs documentation:||no|
|Needs tests:||no||Patch needs improvement:||no|
When using the DB SessionStore, it's possible to start getting a bunch of invalid sessions in the session table. This happens when an original session has been purged from the table, but a client still has the old, stale cookie with the original session ID. The load method will create a new session with a new id for security purposes when it tries to load this old session, but it does *not* update the actual cookie stored on the client. So the client continues to try and use the old session id, which keeps causing the load method to create new sessions with new IDs.
Attached is a simple patch that is the simplest solution I could think of, though I'm not familiar enough with session to understand potential ramifications. The load function is simply updated to set the "modified" property to True so that further processing in the response handler will send an updated version of the cookie to the client.
Change History (4)
Changed 6 years ago by nezroy <nezroy@…>
comment:1 Changed 6 years ago by Simon G <dev@…>
- Needs documentation unset
- Needs tests unset
- Patch needs improvement unset
- Triage Stage changed from Unreviewed to Ready for checkin