-
Notifications
You must be signed in to change notification settings - Fork 1.7k
Default session listings to owned sessions #7970
Copy link
Copy link
Open
Labels
FeatureNew feature or requestNew feature or requestP2-mediumPriority: bug with workaround, important feature requestPriority: bug with workaround, important feature requestcomp:serverComponent: server, API, session managementComponent: server, API, session managementtriagedIssue has been triaged by the botIssue has been triaged by the bot
Description
Activity
Metadata
Metadata
Assignees
Labels
FeatureNew feature or requestNew feature or requestP2-mediumPriority: bug with workaround, important feature requestPriority: bug with workaround, important feature requestcomp:serverComponent: server, API, session managementComponent: server, API, session managementtriagedIssue has been triaged by the botIssue has been triaged by the bot
Description
Session-list requests that omit
visibilitycurrently fetch every accessible active session, including sessions shared by other users. New or external clients can accidentally choose this broad scope. Make ownership the default and require an explicitvisibility=allto include shared sessions.Current behavior / code evidence
At
1d2eae203(0.15.0.dev0), theGET /v1/sessionsroute and Python SDKclient.sessions.list()both default toall. The server'sminebranch also forces archive inclusion off, so changing only the defaults would silently breakinclude_archived=truefor owned sessions.On an authenticated server with one owned session and one session shared by another user, an unfiltered list currently returns both. After this change it should return only the owned session;
visibility=allshould continue returning both.Requested behavior
mine.include_archived=truewithin the owned scope formine.all,shared, andarchivedbehavior and unauthenticated local listings.allmigration path, including archive behavior on older servers.Follow-up to #7949 and #7954. The explicit-visibility lint rule should remain in force.
Environment
Source audit on Linux; affects authenticated multi-user server deployments and the Python SDK, independent of harness.