fix: cookie methods actually work; session builds lazily (v0.1.7)
get_cookies() called filter_cookies() with no URL and always returned {}
for domain-bound cookies; now iterates the jar directly. set_cookie()
ignored path and leaked a shared cookie to every host when given a bare
domain string; scheme is now normalized and path honored, with
domain=None made an intentionally shared cookie instead of a silent
localhost-only no-op.
ExtendedSession also built its aiohttp.ClientSession synchronously in
__init__, which requires a running event loop under aiohttp>=3.14 and
crashed the common construct-before-the-loop-starts host pattern. The
session now builds lazily on first access, preserving the
_create_session subclass override seam used by aioweb_tls.
Signed-off-by: disqualifier <dev@disqualifier.me>
This commit is contained in:
@@ -11,18 +11,18 @@ and swap the HTTP client while inheriting everything else.
|
||||
`requirements.txt`:
|
||||
|
||||
```
|
||||
aioweb @ git+ssh://git@git.rethinkstudios.io/rethink-public/aioweb.git@v0.1.6
|
||||
aioweb @ git+ssh://git@git.rethinkstudios.io/rethink-public/aioweb.git@v0.1.7
|
||||
```
|
||||
|
||||
Direct:
|
||||
|
||||
```bash
|
||||
pip install "aioweb @ git+ssh://git@git.rethinkstudios.io/rethink-public/aioweb.git@v0.1.6"
|
||||
pip install "aioweb @ git+ssh://git@git.rethinkstudios.io/rethink-public/aioweb.git@v0.1.7"
|
||||
```
|
||||
|
||||
Requires `aiohttp` and `yarl` (pulled transitively).
|
||||
|
||||
Drop the `@v0.1.5` suffix from the line above to install the latest unpinned.
|
||||
Drop the `@v0.1.7` suffix from the line above to install the latest unpinned.
|
||||
|
||||
## Usage
|
||||
|
||||
@@ -132,6 +132,29 @@ Two changes can't be shimmed without re-introducing the bugs they fix:
|
||||
|
||||
## Changelog
|
||||
|
||||
### v0.1.7
|
||||
|
||||
- **`get_cookies()` now returns real cookies.** Previously called `filter_cookies()`
|
||||
with no URL, which only ever returns domain-less shared cookies — every normal
|
||||
domain-bound cookie (including ones set by a real `Set-Cookie` response) was
|
||||
silently omitted. Now iterates the jar directly.
|
||||
- **`set_cookie()` no longer leaks a shared cookie to every host.** A bare hostname
|
||||
(`domain="example.com"`) built a schemeless URL, which aiohttp's jar treats as a
|
||||
domain-less "shared" cookie sent with every request the session makes, including
|
||||
unrelated hosts. A scheme is now added when missing so the cookie is scoped to
|
||||
that host.
|
||||
- **`set_cookie()` now honors `path`** (previously ignored — the cookie always
|
||||
landed at `path="/"`). `domain=None` is unchanged in meaning but now stores a
|
||||
truly shared cookie (sent to every host) instead of one silently bound to
|
||||
`localhost` only, which made `set_cookie(name, value)` (no domain) a silent
|
||||
no-op for any real request.
|
||||
- **The backend session is built lazily**, not in `__init__`. Under aiohttp 3.14,
|
||||
constructing `aiohttp.ClientSession` requires a running event loop; eager
|
||||
construction crashed the common host pattern of attaching a session before the
|
||||
loop starts (e.g. `bot.http = ExtendedSession(...)` in `Bot.__init__`). The
|
||||
session (and any subclass's `_create_session` override) now builds on first
|
||||
access instead.
|
||||
|
||||
### v0.1.2
|
||||
|
||||
- Pinned `commons` to v0.2.1 (retry `attempts` floor fix).
|
||||
|
||||
Reference in New Issue
Block a user