Merge the session endpoints into one domain PR - #420
Open
PrestaEdit wants to merge 5 commits into
Open
PrestaEdit wants to merge 5 commits into
PrestaEdit wants to merge 5 commits into
Conversation
Expose the Security session management of the BO (Advanced Parameters >
Security > Sessions) through the Admin API, for both customer and employee
sessions:
GET /customer-sessions paginated list
DELETE /customer-sessions/{sessionId}
DELETE /customer-sessions/bulk-delete
GET /employee-sessions paginated list
DELETE /employee-sessions/{sessionId}
DELETE /employee-sessions/bulk-delete
The ClearOutdated{Customer,Employee}Session commands are deferred to a
follow-up (their natural URI clashes with the Rector pluralization rule).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Expose ClearOutdatedCustomerSessionCommand as DELETE /customer-sessions/bulk-clear-outdated and ClearOutdatedEmployeeSessionCommand as DELETE /employee-sessions/bulk-clear-outdated (scopes customer_session_write / employee_session_write). Uses the 'bulk-' URI prefix so Rector doesn't pluralize the 'clear-outdated' segment. Related to PrestaShop/PrestaShop#39630 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…first segment) Rector's ApiResourceUriTemplateRector derives the first URI segment from the namespace folder (pluralized). Putting the resources under 'Security/' forced '/securities/' as first segment; splitting into 'CustomerSession/' and 'EmployeeSession/' matches the '/customer-sessions/' and '/employee-sessions/' URIs cleanly. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…(default 480h) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Consolidates PrestaShop#272 (customer & employee session list + delete + bulk delete) and PrestaShop#349 (clear-outdated for both). - one SecuritySessionEndpointTest instead of two, so the clear-outdated tests get the resetTables() the standalone class did not have and stopped leaking rows into the other suites - the clear-outdated assertions go through the list endpoint that PrestaShop#272 adds instead of a raw SELECT COUNT(*) on ps_customer_session / ps_employee_session - both tests now seed a current session next to the outdated one and assert the current one survives, which the raw count could not check - one seeding helper per entity, taking the session age as a parameter, instead of two copies of the same INSERT Sessions are created by logging in and the domain has no "add session" command, so the INSERT itself stays: it is the only fixture here that cannot come from the API, and it is now documented as such in a single place. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This was referenced Aug 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR does
Merges #272 and #349 into one PR, following the mutualisation done on the Product domain in #410.
Endpoints
/customer-sessionscustomer_session_read/customer-sessions/{sessionId}customer_session_write/customer-sessions/bulk-deletecustomer_session_write/customer-sessions/bulk-clear-outdatedcustomer_session_write/employee-sessionsemployee_session_read/employee-sessions/{sessionId}employee_session_write/employee-sessions/bulk-deleteemployee_session_write/employee-sessions/bulk-clear-outdatedemployee_session_writeTests
The two test classes become one
SecuritySessionEndpointTest, which is where the merge pays off:SELECT COUNT(*) FROM ps_customer_session WHERE id_customer_session = ..., because it had no list endpoint — Add Security session endpoints (customer & employee: list + delete + bulk delete) #272 has one. Both clear-outdated tests now assert againstGET /customer-sessionsandGET /employee-sessions.ClearOutdatedSessionsEndpointTesthad noresetTables(), so the sessions it seeded stayed in the database for the rest of the suite. It inherits the class-level reset now.INSERT, taking the session age as a parameter.On fixtures: sessions are created by logging in — the domain exposes no "add session" command, so the
INSERTitself has to stay. It is the only fixture here that cannot come from the API, and it now lives in a single documented place per entity. A session older thanPS_COOKIE_LIFETIME_FO/PS_COOKIE_LIFETIME_BO(480 hours by default) is what "outdated" means for the core, hence the-1 yearage.How to test
Same four for
/employee-sessions. Covered bySecuritySessionEndpointTest.Supersedes
Both will be closed once the CI is green here.