Skip to content

Default session listings to owned sessions #7970

Description

@dbczumar

Description

Session-list requests that omit visibility currently fetch every accessible active session, including sessions shared by other users. New or external clients can accidentally choose this broad scope. Make ownership the default and require an explicit visibility=all to include shared sessions.

Current behavior / code evidence

At 1d2eae203 (0.15.0.dev0), the GET /v1/sessions route and Python SDK client.sessions.list() both default to all. The server's mine branch also forces archive inclusion off, so changing only the defaults would silently break include_archived=true for owned sessions.

On an authenticated server with one owned session and one session shared by another user, an unfiltered list currently returns both. After this change it should return only the owned session; visibility=all should continue returning both.

Requested behavior

  • Default the server route and Python SDK to mine.
  • Honor include_archived=true within the owned scope for mine.
  • Preserve explicit all, shared, and archived behavior and unauthenticated local listings.
  • Document this breaking default change and the explicit all migration path, including archive behavior on older servers.

Follow-up to #7949 and #7954. The explicit-visibility lint rule should remain in force.

Environment

Source audit on Linux; affects authenticated multi-user server deployments and the Python SDK, independent of harness.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

FeatureNew feature or requestP2-mediumPriority: bug with workaround, important feature requestcomp:serverComponent: server, API, session managementtriagedIssue has been triaged by the bot

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions