2013-05-16 07:14:28 +08:00
|
|
|
import logging
|
|
|
|
|
2016-01-09 00:08:08 +08:00
|
|
|
from django.contrib.sessions.backends.base import (
|
|
|
|
CreateError, SessionBase, UpdateError,
|
|
|
|
)
|
2007-09-16 05:29:14 +08:00
|
|
|
from django.core.exceptions import SuspiciousOperation
|
2016-01-09 00:08:08 +08:00
|
|
|
from django.db import DatabaseError, IntegrityError, router, transaction
|
2011-11-20 18:33:44 +08:00
|
|
|
from django.utils import timezone
|
2013-05-16 07:14:28 +08:00
|
|
|
from django.utils.encoding import force_text
|
2014-05-17 00:18:34 +08:00
|
|
|
from django.utils.functional import cached_property
|
2010-11-15 07:35:16 +08:00
|
|
|
|
2013-11-03 04:12:09 +08:00
|
|
|
|
2007-09-16 05:29:14 +08:00
|
|
|
class SessionStore(SessionBase):
|
|
|
|
"""
|
2017-01-25 04:31:57 +08:00
|
|
|
Implement database session store.
|
2007-09-16 05:29:14 +08:00
|
|
|
"""
|
2009-12-22 23:18:51 +08:00
|
|
|
def __init__(self, session_key=None):
|
2017-01-21 21:13:44 +08:00
|
|
|
super().__init__(session_key)
|
2009-12-22 23:18:51 +08:00
|
|
|
|
2014-05-17 00:18:34 +08:00
|
|
|
@classmethod
|
|
|
|
def get_model_class(cls):
|
|
|
|
# Avoids a circular import and allows importing SessionStore when
|
|
|
|
# django.contrib.sessions is not in INSTALLED_APPS.
|
|
|
|
from django.contrib.sessions.models import Session
|
|
|
|
return Session
|
|
|
|
|
|
|
|
@cached_property
|
|
|
|
def model(self):
|
|
|
|
return self.get_model_class()
|
|
|
|
|
2007-09-16 05:29:14 +08:00
|
|
|
def load(self):
|
|
|
|
try:
|
2014-05-17 00:18:34 +08:00
|
|
|
s = self.model.objects.get(
|
2012-10-28 01:18:03 +08:00
|
|
|
session_key=self.session_key,
|
2011-11-20 18:33:44 +08:00
|
|
|
expire_date__gt=timezone.now()
|
2007-09-16 05:29:14 +08:00
|
|
|
)
|
2012-08-13 04:26:17 +08:00
|
|
|
return self.decode(s.session_data)
|
2014-05-17 00:18:34 +08:00
|
|
|
except (self.model.DoesNotExist, SuspiciousOperation) as e:
|
2013-05-16 07:14:28 +08:00
|
|
|
if isinstance(e, SuspiciousOperation):
|
2016-03-29 06:33:29 +08:00
|
|
|
logger = logging.getLogger('django.security.%s' % e.__class__.__name__)
|
2013-05-16 07:14:28 +08:00
|
|
|
logger.warning(force_text(e))
|
2015-06-11 05:45:20 +08:00
|
|
|
self._session_key = None
|
2007-09-16 05:29:14 +08:00
|
|
|
return {}
|
2008-01-06 20:53:09 +08:00
|
|
|
|
2007-09-16 05:29:14 +08:00
|
|
|
def exists(self, session_key):
|
2014-05-17 00:18:34 +08:00
|
|
|
return self.model.objects.filter(session_key=session_key).exists()
|
2008-01-06 20:53:09 +08:00
|
|
|
|
2008-08-14 11:57:18 +08:00
|
|
|
def create(self):
|
|
|
|
while True:
|
2011-11-28 01:52:24 +08:00
|
|
|
self._session_key = self._get_new_session_key()
|
2008-08-14 11:57:18 +08:00
|
|
|
try:
|
|
|
|
# Save immediately to ensure we have a unique entry in the
|
|
|
|
# database.
|
|
|
|
self.save(must_create=True)
|
|
|
|
except CreateError:
|
|
|
|
# Key wasn't unique. Try again.
|
|
|
|
continue
|
|
|
|
self.modified = True
|
|
|
|
return
|
|
|
|
|
2014-05-17 00:18:34 +08:00
|
|
|
def create_model_instance(self, data):
|
|
|
|
"""
|
|
|
|
Return a new instance of the session model object, which represents the
|
|
|
|
current session state. Intended to be used for saving the session data
|
|
|
|
to the database.
|
|
|
|
"""
|
|
|
|
return self.model(
|
|
|
|
session_key=self._get_or_create_session_key(),
|
|
|
|
session_data=self.encode(data),
|
|
|
|
expire_date=self.get_expiry_date(),
|
|
|
|
)
|
|
|
|
|
2008-08-14 11:57:18 +08:00
|
|
|
def save(self, must_create=False):
|
|
|
|
"""
|
2017-01-25 04:31:57 +08:00
|
|
|
Save the current session data to the database. If 'must_create' is
|
|
|
|
True, raise a database error if the saving operation doesn't create a
|
|
|
|
new entry (as opposed to possibly updating an existing entry).
|
2008-08-14 11:57:18 +08:00
|
|
|
"""
|
2015-06-11 05:45:20 +08:00
|
|
|
if self.session_key is None:
|
|
|
|
return self.create()
|
2014-05-17 00:18:34 +08:00
|
|
|
data = self._get_session(no_load=must_create)
|
|
|
|
obj = self.create_model_instance(data)
|
|
|
|
using = router.db_for_write(self.model, instance=obj)
|
2008-08-14 11:57:18 +08:00
|
|
|
try:
|
2013-09-23 04:14:17 +08:00
|
|
|
with transaction.atomic(using=using):
|
2016-01-09 00:08:08 +08:00
|
|
|
obj.save(force_insert=must_create, force_update=not must_create, using=using)
|
2008-08-14 11:57:18 +08:00
|
|
|
except IntegrityError:
|
|
|
|
if must_create:
|
|
|
|
raise CreateError
|
|
|
|
raise
|
2016-01-09 00:08:08 +08:00
|
|
|
except DatabaseError:
|
|
|
|
if not must_create:
|
|
|
|
raise UpdateError
|
|
|
|
raise
|
2008-01-06 20:53:09 +08:00
|
|
|
|
2008-08-14 11:57:46 +08:00
|
|
|
def delete(self, session_key=None):
|
|
|
|
if session_key is None:
|
2011-11-28 01:52:24 +08:00
|
|
|
if self.session_key is None:
|
2008-08-15 22:59:11 +08:00
|
|
|
return
|
2011-11-28 01:52:24 +08:00
|
|
|
session_key = self.session_key
|
2007-09-16 05:29:14 +08:00
|
|
|
try:
|
2014-05-17 00:18:34 +08:00
|
|
|
self.model.objects.get(session_key=session_key).delete()
|
|
|
|
except self.model.DoesNotExist:
|
2008-01-06 20:53:09 +08:00
|
|
|
pass
|
2010-11-15 07:35:16 +08:00
|
|
|
|
2012-10-28 05:12:08 +08:00
|
|
|
@classmethod
|
|
|
|
def clear_expired(cls):
|
2014-05-17 00:18:34 +08:00
|
|
|
cls.get_model_class().objects.filter(expire_date__lt=timezone.now()).delete()
|