Make get_current_user async and update DELETE /auth/me #798

Closed
opened 2026-09-23 17:56:30 +00:00 by gambit-admin · 1 comment
Owner

Reported by @zfarrington. The get_current_user dependency is a plain def using a sync Session, so every authenticated request consumes a sync connection for the auth lookup while the async route and its SELECT use another connection and open a transaction that is never committed, holding that connection for the whole request. Risk: doubles connection use on every authenticated call; because it is sync def, an exhausted pool can block a threadpool thread for up to 60s. If enough authenticated requests hit this, nobody can authenticate, causing a full outage. Fix: convert get_current_user to async def using AsyncSession and cache the lookup for the token's lifetime so a cache hit skips the database entirely. Update DELETE /auth/me in the same change so it works with the converted dependency: change db.delete(user) to db.delete(db.get(User, user.id)), since it holds a separate sync session.


Reported via Mattermost bot by Gambit Agent

Reported by @zfarrington. The get_current_user dependency is a plain def using a sync Session, so every authenticated request consumes a sync connection for the auth lookup while the async route and its SELECT use another connection and open a transaction that is never committed, holding that connection for the whole request. Risk: doubles connection use on every authenticated call; because it is sync def, an exhausted pool can block a threadpool thread for up to 60s. If enough authenticated requests hit this, nobody can authenticate, causing a full outage. Fix: convert get_current_user to async def using AsyncSession and cache the lookup for the token's lifetime so a cache hit skips the database entirely. Update DELETE /auth/me in the same change so it works with the converted dependency: change db.delete(user) to db.delete(db.get(User, user.id)), since it holds a separate sync session. --- Reported via Mattermost bot by Gambit Agent
gambit-admin added the bugapiperformance labels 2026-09-23 17:56:30 +00:00
gambit-admin added the claimed:Kelly label 2026-09-25 01:01:39 +00:00
Author
Owner

PR opened: https://github.com/Gambit-Inc/gambit/pull/582 — get_current_user is now async on the request's AsyncSession with a Redis-cached snapshot (60s TTL, invalidated on every commit that changes a user). DELETE /auth/me loads and deletes its own row, and also no longer 409s for the last login on a vendor (pre-existing autoflush bug on Postgres).

PR opened: https://github.com/Gambit-Inc/gambit/pull/582 — get_current_user is now async on the request's AsyncSession with a Redis-cached snapshot (60s TTL, invalidated on every commit that changes a user). DELETE /auth/me loads and deletes its own row, and also no longer 409s for the last login on a vendor (pre-existing autoflush bug on Postgres).
Sign in to join this conversation.