-
Notifications
You must be signed in to change notification settings - Fork 25
Expand file tree
/
Copy pathmiddleware.py
More file actions
60 lines (45 loc) · 1.92 KB
/
middleware.py
File metadata and controls
60 lines (45 loc) · 1.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
import time
import re
from django.conf import settings
from django.contrib.auth.views import redirect_to_login
from django.shortcuts import redirect
try:
from django.utils.deprecation import MiddlewareMixin
except ImportError:
MiddlewareMixin = object
SESSION_TIMEOUT_KEY = "_session_init_timestamp_"
class SessionTimeoutMiddleware(MiddlewareMixin):
def __init__(self, get_response=None):
self.get_response = get_response
self.ignored_paths_regex = None
regex = getattr(settings, "SESSION_ACTIVITY_IGNORED_PATHS_REGEX", None)
if regex:
self.ignored_paths_regex = re.compile(regex)
def is_path_ignored(self, path):
ignored = self.ignored_paths_regex and bool(self.ignored_paths_regex.search(path))
return ignored
def process_request(self, request):
if not hasattr(request, "session") or request.session.is_empty():
return
init_time = request.session.setdefault(SESSION_TIMEOUT_KEY, time.time())
expire_seconds = getattr(
settings, "SESSION_EXPIRE_SECONDS", settings.SESSION_COOKIE_AGE
)
session_is_expired = time.time() - init_time > expire_seconds
if session_is_expired:
request.session.flush()
redirect_url = getattr(settings, "SESSION_TIMEOUT_REDIRECT", None)
if redirect_url:
return redirect(redirect_url)
else:
return redirect_to_login(next=request.path)
expire_since_last_activity = getattr(
settings, "SESSION_EXPIRE_AFTER_LAST_ACTIVITY", False
)
grace_period = getattr(
settings, "SESSION_EXPIRE_AFTER_LAST_ACTIVITY_GRACE_PERIOD", 1
)
if expire_since_last_activity \
and time.time() - init_time > grace_period \
and not self.is_path_ignored(request.path):
request.session[SESSION_TIMEOUT_KEY] = time.time()