always reset the session when auth session expires
This commit is contained in:
@@ -1 +1 @@
|
|||||||
Version 2.9.2-stable+timestamp.2014.03.02.17.46.39
|
Version 2.9.2-stable+timestamp.2014.03.03.08.43.05
|
||||||
|
|||||||
+17
-6
@@ -1153,12 +1153,23 @@ class Auth(object):
|
|||||||
self.user_groups = auth and auth.user_groups or {}
|
self.user_groups = auth and auth.user_groups or {}
|
||||||
if secure:
|
if secure:
|
||||||
request.requires_https()
|
request.requires_https()
|
||||||
if auth and auth.last_visit and auth.last_visit + \
|
now = request.now
|
||||||
datetime.timedelta(days=0, seconds=auth.expiration) > request.now:
|
# if we have auth info
|
||||||
self.user = auth.user
|
# if not expired it, used it
|
||||||
# this is a trick to speed up sessions
|
# if expired, clear the session
|
||||||
if (request.now - auth.last_visit).seconds > (auth.expiration / 10):
|
# else, only clear auth info in the session
|
||||||
auth.last_visit = request.now
|
if auth:
|
||||||
|
delta = datetime.timedelta(days=0, seconds=auth.expiration)
|
||||||
|
if auth.last_visit and auth.last_visit + delta > now:
|
||||||
|
self.user = auth.user
|
||||||
|
# this is a trick to speed up sessions to avoid many writes
|
||||||
|
if (now - auth.last_visit).seconds > (auth.expiration / 10):
|
||||||
|
auth.last_visit = request.now
|
||||||
|
else:
|
||||||
|
self.user = None
|
||||||
|
if session.auth:
|
||||||
|
del session.auth
|
||||||
|
session.renew(clear_session=True)
|
||||||
else:
|
else:
|
||||||
self.user = None
|
self.user = None
|
||||||
if session.auth:
|
if session.auth:
|
||||||
|
|||||||
Reference in New Issue
Block a user