Verified Commit 4bf14a08 authored by Dave Long's avatar Dave Long
Browse files

refactor: #3570849 Deprecate SessionManager::delete()

By: znerol
By: dcam
By: godotislate
(cherry picked from commit 29b81b3c)
parent be296a78
Loading
Loading
Loading
Loading
Loading
+6 −5
Changes for core/core.services.yml: 6 added lines, 5 removed lines.
Original line number Diff line number Diff line
@@ -1723,6 +1723,11 @@ services:
    class: Symfony\Component\HttpFoundation\Session\Attribute\AttributeBag
    public: false
  Symfony\Component\HttpFoundation\Session\Attribute\AttributeBagInterface: '@session.attribute_bag'
  Drupal\Core\Session\UserSessionRepositoryInterface:
    class: Drupal\Core\Session\UserSessionRepository
    autowire: true
    tags:
      - { name: backend_overridable }
  session_handler:
    alias: session_handler.storage
  session_handler.storage:
@@ -1737,11 +1742,7 @@ services:
  Drupal\Core\Session\WriteSafeSessionHandlerInterface: '@session_handler.write_safe'
  session_manager:
    class: Drupal\Core\Session\SessionManager
    arguments: ['@request_stack', '@database', '@session_manager.metadata_bag', '@session_configuration', '@datetime.time', '@session_handler']
    tags:
      - { name: backend_overridable }
    calls:
      - [setWriteSafeHandler, ['@session_handler.write_safe']]
    arguments: ['@request_stack', '@session_handler', '@session_manager.metadata_bag', '@session_configuration', '@datetime.time', '@Drupal\Core\Session\UserSessionRepositoryInterface']
  Drupal\Core\Session\SessionManagerInterface: '@session_manager'
  session_manager.metadata_bag:
    class: Drupal\Core\Session\MetadataBag
+23 −26
Changes for core/lib/Drupal/Core/Session/SessionManager.php: 23 added lines, 26 removed lines.
Original line number Diff line number Diff line
@@ -8,6 +8,7 @@
use Symfony\Component\HttpFoundation\RequestStack;
use Symfony\Component\HttpFoundation\Session\SessionBagInterface;
use Symfony\Component\HttpFoundation\Session\Storage\NativeSessionStorage;
use Symfony\Component\HttpFoundation\Session\Storage\Proxy\AbstractProxy;

/**
 * Manages user sessions.
@@ -37,42 +38,50 @@ class SessionManager extends NativeSessionStorage implements SessionManagerInter
  protected $startedLazy;

  /**
   * The write safe session handler.
   *
   * @var \Drupal\Core\Session\WriteSafeSessionHandlerInterface
   *
   * @todo This reference should be removed once all database queries
   *   are removed from the session manager class.
   * The user session repository.
   */
  protected $writeSafeHandler;
  protected UserSessionRepositoryInterface $sessionRepository;

  /**
   * Constructs a new session manager instance.
   *
   * @param \Symfony\Component\HttpFoundation\RequestStack $requestStack
   *   The request stack.
   * @param \Drupal\Core\Database\Connection $connection
   *   The database connection.
   * @param \Symfony\Component\HttpFoundation\Session\Storage\Proxy\AbstractProxy|\SessionHandlerInterface|null $handler
   *   The object to register as a PHP session handler.
   * @param \Drupal\Core\Session\MetadataBag $metadata_bag
   *   The session metadata bag.
   * @param \Drupal\Core\Session\SessionConfigurationInterface $sessionConfiguration
   *   The session configuration interface.
   * @param \Drupal\Component\Datetime\TimeInterface $time
   *   The time service.
   * @param \Symfony\Component\HttpFoundation\Session\Storage\Proxy\AbstractProxy|\SessionHandlerInterface|null $handler
   *   The object to register as a PHP session handler.
   * @param \Drupal\Core\Session\UserSessionRepositoryInterface $session_repository
   *   The user session repository.
   *
   * @see \Symfony\Component\HttpFoundation\Session\Storage\NativeSessionStorage::setSaveHandler()
   */
  public function __construct(
    protected RequestStack $requestStack,
    protected Connection $connection,
    Connection|AbstractProxy|\SessionHandlerInterface|null $handler,
    MetadataBag $metadata_bag,
    protected SessionConfigurationInterface $sessionConfiguration,
    protected TimeInterface $time,
    $handler = NULL,
    $session_repository = NULL,
  ) {
    // The second parameter ($handler) used to be the database connection. And
    // the last parameter ($session_repository) used to be $handler. Rearrange
    // the parameters if constructor was called like this.
    if ($handler instanceof Connection && !$session_repository instanceof UserSessionRepositoryInterface) {
      @trigger_error('Calling ' . __METHOD__ . '() with a database $connection as the second argument is deprecated in drupal:11.4.0 and it will throw an error in drupal:12.0.0. See https://www.drupal.org/node/3570851', E_USER_DEPRECATED);
      $handler = $session_repository;
    }
    parent::__construct([], $handler, $metadata_bag);
    if ($session_repository instanceof UserSessionRepositoryInterface) {
      $this->sessionRepository = $session_repository;
    }
    else {
      $this->sessionRepository = \Drupal::service(UserSessionRepositoryInterface::class);
    }
  }

  /**
@@ -206,18 +215,7 @@ public function regenerate($destroy = FALSE, $lifetime = NULL): bool {
   * {@inheritdoc}
   */
  public function delete($uid) {
    // Nothing to do if we are not allowed to change the session.
    if (!$this->writeSafeHandler->isSessionWritable() || $this->isCli()) {
      return;
    }
    // The sessions table may not have been created yet.
    try {
      $this->connection->delete('sessions')
        ->condition('uid', $uid)
        ->execute();
    }
    catch (\Exception) {
    }
    $this->sessionRepository->deleteAll($uid);
  }

  /**
@@ -251,7 +249,6 @@ public function destroy() {
   * {@inheritdoc}
   */
  public function setWriteSafeHandler(WriteSafeSessionHandlerInterface $handler) {
    $this->writeSafeHandler = $handler;
  }

  /**
+8 −0
Changes for core/lib/Drupal/Core/Session/SessionManagerInterface.php: 8 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -14,6 +14,10 @@ interface SessionManagerInterface extends SessionStorageInterface {
   *
   * @param int $uid
   *   User ID.
   *
   * @deprecated in drupal:11.4.0 and is removed from drupal:12.0.0. Use
   * Drupal\user\UserSessionRepositoryInterface::deleteAll() instead.
   * @see https://www.drupal.org/node/3570851
   */
  public function delete($uid);

@@ -29,6 +33,10 @@ public function destroy();
   *   the session manager class.
   *
   * @var \Drupal\Core\Session\WriteSafeSessionHandlerInterface
   *
   * @deprecated in drupal:11.4.0 and is removed from drupal:12.0.0. There is no
   * replacement.
   * @see https://www.drupal.org/node/3570851
   */
  public function setWriteSafeHandler(WriteSafeSessionHandlerInterface $handler);

+32 −0
Changes for core/lib/Drupal/Core/Session/UserSessionRepository.php: 32 added lines, 0 removed lines.
Original line number Diff line number Diff line
<?php

declare(strict_types=1);

namespace Drupal\Core\Session;

use Drupal\Core\Database\Connection;

/**
 * Provides the default user session repository.
 */
readonly class UserSessionRepository implements UserSessionRepositoryInterface {

  public function __construct(protected Connection $connection) {
  }

  /**
   * {@inheritdoc}
   */
  public function deleteAll(int $uid): void {
    try {
      // Delete session data.
      $this->connection->delete('sessions')
        ->condition('uid', $uid)
        ->execute();
    }
    // Swallow the error if the table hasn't been created yet.
    catch (\Exception) {
    }
  }

}
+20 −0
Changes for core/lib/Drupal/Core/Session/UserSessionRepositoryInterface.php: 20 added lines, 0 removed lines.
Original line number Diff line number Diff line
<?php

declare(strict_types=1);

namespace Drupal\Core\Session;

/**
 * Provides an interface for the user session repository.
 */
interface UserSessionRepositoryInterface {

  /**
   * Delete all session records of the given user.
   *
   * @param int $uid
   *   The user id.
   */
  public function deleteAll(int $uid): void;

}
Loading