Files
Gitea/modules/session/db.go
T
silverwind cf89ecd887 refactor!: move go-chi/session into Gitea (#39504)
The `gitea.com/go-chi/session` package only exists for Gitea, so it
moves into `modules/session` to fix its bugs directly. Fixes the flake
in
https://github.com/go-gitea/gitea/actions/runs/36726154500/job/109923538400.

- Sessions are only written back when changed, so a read-only request
can't revert a concurrent change or restore a logged-out session, like
https://github.com/go-macaron/session/commit/ae808a4a4660c802965c834299ab08f167effd12
- The session cookie is only set once a session holds data
- Every backend refreshes the expiry on load and file sessions are
written atomically
- Also fix  https://github.com/go-gitea/gitea/issues/36176

## ⚠️ BREAKING ⚠️

* the `mysql`, `postgres`, `couchbase` and `memcache` session providers
are removed, use `file`, `db` or `redis` instead
* login-related cookies are renamed to `gitea_session` and
`gitea_remember`, if you'd like to use the old names, set `COOKIE_NAME`
and `COOKIE_REMEMBER_NAME` in app.ini

---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-02 21:08:14 +02:00

43 lines
1020 B
Go

// Copyright 2020 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT
package session
import (
"context"
"gitea.dev/models/auth"
"gitea.dev/modules/log"
"gitea.dev/modules/timeutil"
)
type dbBackend struct {
maxLifetime int64
}
func dbContext() context.Context {
return context.Background()
}
func (b *dbBackend) load(sid string) ([]byte, error) {
sess, exist, err := auth.GetSession(dbContext(), sid)
if err != nil || !exist || sess.LastAccessTime.Add(b.maxLifetime) <= timeutil.TimeStampNow() {
return nil, err
}
return sess.Data, auth.UpdateSessionLastAccessTime(dbContext(), sid)
}
func (b *dbBackend) save(sid string, data []byte, create bool) error {
return auth.UpdateSession(dbContext(), sid, data, create)
}
func (b *dbBackend) destroy(sid string) error {
return auth.DestroySession(dbContext(), sid)
}
func (b *dbBackend) gc() {
if err := auth.CleanupSessions(dbContext(), b.maxLifetime); err != nil {
log.Error("Unable to garbage collect sessions: %v", err)
}
}