Skip to content

[rejected AI] fix: do not mark session accessed in process_response - #481

Closed
r3wretrhy wants to merge 1 commit into
pallets:mainfrom
r3wretrhy:fix/session-vary-cookie-480
Closed

r3wretrhy wants to merge 1 commit into
pallets:mainfrom
r3wretrhy:fix/session-vary-cookie-480

Conversation

@r3wretrhy

Copy link
Copy Markdown

process_response / postprocess_websocket were reading ctx.session, which sets session.accessed = True. That forced SecureCookieSessionInterface.save_session to add Vary: Cookie on every response, including views that never touched the session (and static files).

Use ctx._session instead (same idea as Flask's ctx._get_session()), and only save when a real session object is present.

fixes #480

Reading ctx.session sets session.accessed, which made
SecureCookieSessionInterface.save_session add Vary: Cookie on every
response — including views that never touched the session. Use
ctx._session instead, matching Flask's ctx._get_session() pattern.

Fixes pallets#480
@davidism

davidism commented Oct 1, 2026

Copy link
Copy Markdown
Member

@davidism davidism closed this Oct 1, 2026
@davidism davidism changed the title fix: do not mark session accessed in process_response [rejected AI] fix: do not mark session accessed in process_response Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

process_response marks the session accessed, so every response gets Vary: Cookie

2 participants