Skip to content

Add Security session endpoints (customer & employee: list + delete + bulk delete) - #272

Closed
PrestaEdit wants to merge 1 commit into
PrestaShop:devfrom
PrestaEdit:add-security-sessions
Closed

PrestaEdit wants to merge 1 commit into
PrestaShop:devfrom
PrestaEdit:add-security-sessions

Conversation

@PrestaEdit

Copy link
Copy Markdown
Contributor
Questions Answers
Branch? dev
Description? Exposes the BO Security > Sessions management through the Admin API, for both customer and employee sessions.
- GET /customer-sessions paginated list (scope customer_session_read)
- DELETE /customer-sessions/{sessionId} (scope customer_session_write)
- DELETE /customer-sessions/bulk-delete (scope customer_session_write)
- GET /employee-sessions paginated list (scope employee_session_read)
- DELETE /employee-sessions/{sessionId} (scope employee_session_write)
- DELETE /employee-sessions/bulk-delete (scope employee_session_write)

The ClearOutdated{Customer,Employee}Session commands are deferred to a follow-up (their natural URI clashes with the Rector pluralization rule).
Type? new feature
Category? WS
BC breaks? no
Deprecations? no
Fixed ticket? Part of PrestaShop/PrestaShop#39630
How to test? Run SecuritySessionEndpointTest. It seeds rows in customer_session / employee_session, lists them via GET /customer-sessions / GET /employee-sessions, deletes one via DELETE /…-sessions/{sessionId}, and removes several at once via DELETE /…-sessions/bulk-delete with { sessionIds }.
Sponsor company

Exposes the customer & employee session listing + delete + bulk-delete of the Security domain. All commands take scalar ctor args (int $sessionId / array $sessionIds) so there is no value-object-as-scalar issue, and the lists reuse the existing prestashop.core.grid.data_factory.security.session.{customer,employee} grid factories. All underlying CQRS classes were verified to exist as of tag 9.0.3, so this is compatible with the lower bound of the CI test matrix.

Expose the Security session management of the BO (Advanced Parameters >
Security > Sessions) through the Admin API, for both customer and employee
sessions:
  GET    /customer-sessions            paginated list
  DELETE /customer-sessions/{sessionId}
  DELETE /customer-sessions/bulk-delete
  GET    /employee-sessions            paginated list
  DELETE /employee-sessions/{sessionId}
  DELETE /employee-sessions/bulk-delete

The ClearOutdated{Customer,Employee}Session commands are deferred to a
follow-up (their natural URI clashes with the Rector pluralization rule).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@PrestaEdit

Copy link
Copy Markdown
Contributor Author

Superseded by #420, which merges this endpoint with the rest of the domain, following the mutualisation asked for by the core team (one PR per domain rather than one per endpoint).

The consolidated PR is green and lists what changed for this endpoint on the way in. Closing here to keep the review in one place.

@PrestaEdit PrestaEdit closed this Aug 20, 2026
@github-project-automation github-project-automation Bot moved this from Ready for review to Closed in PR Dashboard Aug 20, 2026
@ps-jarvis ps-jarvis moved this from Closed to Ready for review in PR Dashboard Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

2 participants