fix: refresh auth freshness during active sessions
Some checks failed
CI / python-validation (push) Has been cancelled
CI / docker-release-gate (push) Has been cancelled
i18n / compile-translations (push) Has been cancelled

This commit is contained in:
Md Bayazid Bostame
2026-04-01 17:48:04 +02:00
parent 6254a059b4
commit 5fab01d57a
2 changed files with 23 additions and 1 deletions

View File

@@ -154,7 +154,10 @@ class AuthSessionHardeningMiddleware:
def _touch_session(self, request, now_ts: int) -> None:
request.session['last_activity_ts'] = now_ts
request.session.setdefault('auth_fresh_ts', now_ts)
if request.method in {'GET', 'HEAD'}:
request.session['auth_fresh_ts'] = now_ts
else:
request.session.setdefault('auth_fresh_ts', now_ts)
def _warn(self, request, message: str) -> None:
try: