【问题标题】:flask: get session time remaining via AJAXflask:通过 AJAX 获取会话剩余时间
【发布时间】:2016-09-03 03:38:45
【问题描述】:

我正在使用 Flask,带有用于存储在 Redis 后端中的服务器端会话的 flask-session 插件。我有烧瓶设置使用持久会话,会话超时。如何在不重置超时的情况下发出 AJAX 请求以获取会话的剩余时间?

这个想法是让客户端在显示超时警告(或注销用户)之前检查服务器,以防用户在同一浏览器的不同选项卡/窗口中处于活动状态。

编辑:经过一番挖掘,我找到了配置指令SESSION_REFRESH_EACH_REQUEST,它出现我应该能够使用它来完成我想要的:将其设置为 False,然后会话应该仅当会话中发生实际更改时才会刷新,因此我应该能够在不更改会话超时的情况下发出请求以获取超时。它是在 0.11 中添加的,我正在运行 0.11.1,所以它应该可用。

不幸的是,实际上这似乎不起作用 - 至少在检查 redis 键的ttl 以获得剩余时间时。我查了一下,session.modified 是 False,所以不仅仅是我在修改会话的请求中做了一些事情(除非它只是没有设置那个标志)

【问题讨论】:

    标签: python ajax session flask


    【解决方案1】:

    以下工作,虽然它是相当hacky:

    在应用程序__init__.py,或任何你调用Session(app)或init_app(app)的地方:

    #set up the session
    Session(app)
    
    # Save a reference to the original save_session function so we can call it
    original_save_session = app.session_interface.save_session
    
    #----------------------------------------------------------------------
    def discretionary_save_session(self, *args, **kwargs):
        """A wrapper for the save_session function of the app session interface to
        allow the option of not saving the session when calling specific functions,
        for example if the client needs to get information about the session
        (say, expiration time) without changing the session."""
    
        # bypass: list of functions on which we do NOT want to update the session when called
        # This could be put in the config or the like
        #
        # Improvement idea: "mark" functions on which we want to bypass saving in
        # some way, then check for that mark here, rather than having a hard-coded list.
        bypass = ['check_timeout']
    
        #convert function names to URL's
        bypass = [flask.url_for(x) for x in bypass]
    
        if not flask.request.path in bypass:
            # if the current request path isn't in our bypass list, go ahead and
            # save the session normally
            return original_save_session(self, *args, **kwargs)
    
    # Override the save_session function to ours
    app.session_interface.save_session = discretionary_save_session
    

    然后,在check_timeout 函数中(在上面的旁路列表中),我们可以执行以下操作来获取会话的剩余时间:

    @app.route('/auth/check_timeout')
    def check_timeout():
        """"""
        session_id = flask.session.sid
    
        # Or however you want to get a redis instance
        redis = app.config.get('REDIS_MASTER')
    
        # If used
        session_prefix = app.config.get('SESSION_KEY_PREFIX')
    
        #combine prefix and session id to get the session key stored in redis
        redis_key = "{}{}".format(session_prefix, session_id)
    
        # The redis ttl is the time remaining before the session expires
        time_remain = redis.ttl(redis_key)
    
        return str(time_remain)
    

    我确信以上内容可以改进,但结果如预期:调用/auth/check_timeout时,会话剩余时间返回,而不以任何方式修改会话。

    【讨论】:

      猜你喜欢
      • 2013-01-20
      • 1970-01-01
      • 1970-01-01
      • 2016-07-10
      • 1970-01-01
      • 1970-01-01
      • 2019-11-02
      • 1970-01-01
      • 2018-05-01
      相关资源
      最近更新 更多