Make get_current_user async and update DELETE /auth/me #798
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Reported by @zfarrington. The get_current_user dependency is a plain def using a sync Session, so every authenticated request consumes a sync connection for the auth lookup while the async route and its SELECT use another connection and open a transaction that is never committed, holding that connection for the whole request. Risk: doubles connection use on every authenticated call; because it is sync def, an exhausted pool can block a threadpool thread for up to 60s. If enough authenticated requests hit this, nobody can authenticate, causing a full outage. Fix: convert get_current_user to async def using AsyncSession and cache the lookup for the token's lifetime so a cache hit skips the database entirely. Update DELETE /auth/me in the same change so it works with the converted dependency: change db.delete(user) to db.delete(db.get(User, user.id)), since it holds a separate sync session.
Reported via Mattermost bot by Gambit Agent
PR opened: https://github.com/Gambit-Inc/gambit/pull/582 — get_current_user is now async on the request's AsyncSession with a Redis-cached snapshot (60s TTL, invalidated on every commit that changes a user). DELETE /auth/me loads and deletes its own row, and also no longer 409s for the last login on a vendor (pre-existing autoflush bug on Postgres).