Skip to content

Merge the session endpoints into one domain PR - #420

Open
PrestaEdit wants to merge 5 commits into
PrestaShop:devfrom
PrestaEdit:domain/sessions
Open

PrestaEdit wants to merge 5 commits into
PrestaShop:devfrom
PrestaEdit:domain/sessions

Conversation

@PrestaEdit

Copy link
Copy Markdown
Contributor
Questions Answers
Branch? dev
Description? Consolidates the customer/employee session PRs into one domain PR, with the clear-outdated tests asserting through the list endpoint
Type? new feature
BC breaks? no
Deprecations? no
Fixed ticket? Related to PrestaShop/PrestaShop#39630
How to test? See below
Sponsor company PrestaEdit

What this PR does

Merges #272 and #349 into one PR, following the mutualisation done on the Product domain in #410.

Endpoints

Method URI Scope
GET /customer-sessions customer_session_read
DELETE /customer-sessions/{sessionId} customer_session_write
DELETE /customer-sessions/bulk-delete customer_session_write
DELETE /customer-sessions/bulk-clear-outdated customer_session_write
GET /employee-sessions employee_session_read
DELETE /employee-sessions/{sessionId} employee_session_write
DELETE /employee-sessions/bulk-delete employee_session_write
DELETE /employee-sessions/bulk-clear-outdated employee_session_write

Tests

The two test classes become one SecuritySessionEndpointTest, which is where the merge pays off:

  • The clear-outdated assertions now go through the API. Add clear-outdated sessions endpoints (customer + employee) #349 checked its work with SELECT COUNT(*) FROM ps_customer_session WHERE id_customer_session = ..., because it had no list endpoint — Add Security session endpoints (customer & employee: list + delete + bulk delete) #272 has one. Both clear-outdated tests now assert against GET /customer-sessions and GET /employee-sessions.
  • They actually verify what the endpoint promises. Each test now seeds a current session alongside the outdated one and asserts the current one is still listed afterwards. The raw count could only tell that the outdated row was gone, not that the endpoint had left everything else alone.
  • The leak is fixed. ClearOutdatedSessionsEndpointTest had no resetTables(), so the sessions it seeded stayed in the database for the rest of the suite. It inherits the class-level reset now.
  • One seeding helper per entity instead of two copies of the same INSERT, taking the session age as a parameter.

On fixtures: sessions are created by logging in — the domain exposes no "add session" command, so the INSERT itself has to stay. It is the only fixture here that cannot come from the API, and it now lives in a single documented place per entity. A session older than PS_COOKIE_LIFETIME_FO / PS_COOKIE_LIFETIME_BO (480 hours by default) is what "outdated" means for the core, hence the -1 year age.

How to test

GET    /customer-sessions                       -> 200, paginated list
DELETE /customer-sessions/{id}                  -> 204, then it is no longer listed
DELETE /customer-sessions/bulk-delete           -> 204, then none of them are listed
DELETE /customer-sessions/bulk-clear-outdated   -> 204, the outdated one goes, the current one stays

Same four for /employee-sessions. Covered by SecuritySessionEndpointTest.

Supersedes

Both will be closed once the CI is green here.

PrestaEdit and others added 5 commits August 20, 2026 10:44
Expose the Security session management of the BO (Advanced Parameters >
Security > Sessions) through the Admin API, for both customer and employee
sessions:
  GET    /customer-sessions            paginated list
  DELETE /customer-sessions/{sessionId}
  DELETE /customer-sessions/bulk-delete
  GET    /employee-sessions            paginated list
  DELETE /employee-sessions/{sessionId}
  DELETE /employee-sessions/bulk-delete

The ClearOutdated{Customer,Employee}Session commands are deferred to a
follow-up (their natural URI clashes with the Rector pluralization rule).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Expose ClearOutdatedCustomerSessionCommand as DELETE /customer-sessions/bulk-clear-outdated
and ClearOutdatedEmployeeSessionCommand as DELETE /employee-sessions/bulk-clear-outdated
(scopes customer_session_write / employee_session_write). Uses the 'bulk-' URI prefix
so Rector doesn't pluralize the 'clear-outdated' segment.

Related to PrestaShop/PrestaShop#39630

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…first segment)

Rector's ApiResourceUriTemplateRector derives the first URI segment from the
namespace folder (pluralized). Putting the resources under 'Security/' forced
'/securities/' as first segment; splitting into 'CustomerSession/' and
'EmployeeSession/' matches the '/customer-sessions/' and '/employee-sessions/'
URIs cleanly.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…(default 480h)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Consolidates PrestaShop#272 (customer & employee session list + delete + bulk delete) and
PrestaShop#349 (clear-outdated for both).

- one SecuritySessionEndpointTest instead of two, so the clear-outdated tests get
  the resetTables() the standalone class did not have and stopped leaking rows into
  the other suites
- the clear-outdated assertions go through the list endpoint that PrestaShop#272 adds instead
  of a raw SELECT COUNT(*) on ps_customer_session / ps_employee_session
- both tests now seed a current session next to the outdated one and assert the
  current one survives, which the raw count could not check
- one seeding helper per entity, taking the session age as a parameter, instead of
  two copies of the same INSERT

Sessions are created by logging in and the domain has no "add session" command, so
the INSERT itself stays: it is the only fixture here that cannot come from the API,
and it is now documented as such in a single place.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Ready for review

Development

Successfully merging this pull request may close these issues.

2 participants