Add Security session endpoints (customer & employee: list + delete + bulk delete) - #272
Closed
PrestaEdit wants to merge 1 commit into
Closed
PrestaEdit wants to merge 1 commit into
PrestaEdit wants to merge 1 commit into
Conversation
Expose the Security session management of the BO (Advanced Parameters >
Security > Sessions) through the Admin API, for both customer and employee
sessions:
GET /customer-sessions paginated list
DELETE /customer-sessions/{sessionId}
DELETE /customer-sessions/bulk-delete
GET /employee-sessions paginated list
DELETE /employee-sessions/{sessionId}
DELETE /employee-sessions/bulk-delete
The ClearOutdated{Customer,Employee}Session commands are deferred to a
follow-up (their natural URI clashes with the Rector pluralization rule).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
PrestaEdit
marked this pull request as ready for review
July 8, 2026 08:08
PrestaEdit
marked this pull request as draft
August 20, 2026 08:22
Contributor
Author
|
Superseded by #420, which merges this endpoint with the rest of the domain, following the mutualisation asked for by the core team (one PR per domain rather than one per endpoint). The consolidated PR is green and lists what changed for this endpoint on the way in. Closing here to keep the review in one place. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
-
GET /customer-sessionspaginated list (scopecustomer_session_read)-
DELETE /customer-sessions/{sessionId}(scopecustomer_session_write)-
DELETE /customer-sessions/bulk-delete(scopecustomer_session_write)-
GET /employee-sessionspaginated list (scopeemployee_session_read)-
DELETE /employee-sessions/{sessionId}(scopeemployee_session_write)-
DELETE /employee-sessions/bulk-delete(scopeemployee_session_write)The
ClearOutdated{Customer,Employee}Sessioncommands are deferred to a follow-up (their natural URI clashes with the Rector pluralization rule).SecuritySessionEndpointTest. It seeds rows incustomer_session/employee_session, lists them viaGET /customer-sessions/GET /employee-sessions, deletes one viaDELETE /…-sessions/{sessionId}, and removes several at once viaDELETE /…-sessions/bulk-deletewith{ sessionIds }.Exposes the customer & employee session listing + delete + bulk-delete of the
Securitydomain. All commands take scalar ctor args (int $sessionId/array $sessionIds) so there is no value-object-as-scalar issue, and the lists reuse the existingprestashop.core.grid.data_factory.security.session.{customer,employee}grid factories. All underlying CQRS classes were verified to exist as of tag9.0.3, so this is compatible with the lower bound of the CI test matrix.