* fix: před stahováním ověřit přihlášení přes islogged Server při vypršelé session nevrací chybu, ale tiše odpoví jako anonymnímu uživateli (jen přístupnost A). Plugin proto před stahováním volá /api/user/islogged; při 'nologged' se jednou znovu přihlásí z uložených údajů, a když to nejde, varuje v liště, že stahuje anonymně. - amcr_tools: _check_islogged, _ensure_logged_in, volání v load_amcr_data - smoke test: 7 offline scénářů stavu přihlášení - README; changelog v2.2.0 v metadata.txt - openspec/changes/fix-session-expiry-islogged: návrh, spec, design, úkoly Closes #72. Připraveno s pomocí AI (Claude), ručně zkontrolováno. * feat: odebrání přihlašovacích údajů uživatele i odhlásí Dosud zůstala přihlášená session v paměti až do restartu QGIS, takže se po „Odebrat uložené přihlašovací údaje“ dál stahovalo jako přihlášený. Nově se session odhlásí na serveru (GET /api/user/logout) a zahodí; když server neodpoví, zahodí se aspoň lokálně. - amcr_tools: logout_from_api; amcr_dialog: volání v _forget_credentials - smoke test: odhlášení, chyba sítě, bez session - README, changelog v2.2.0, OpenSpec (požadavek + úkoly 2b; 3.3 ověřeno) Připraveno s pomocí AI (Claude), ručně zkontrolováno. * chore: archivovat OpenSpec změnu fix-session-expiry-islogged Všechny úkoly hotové (2b.2 – odhlášení – ověřeno ručně v QGIS), archivováno s --skip-specs (stupeň change-tracked, bez openspec/specs/). Připraveno s pomocí AI (Claude), ručně zkontrolováno.
3.4 KiB
Spec Delta
Purpose
Keeps a logged-in user's data downloads from digiarchiv running under a valid login, and makes it visible when a download falls back to anonymous access.
ADDED Requirements
Requirement: Login state is verified before a download
Before starting a data download, the plugin SHALL ask the server whether the current session is logged in, whenever an in-memory session exists or login credentials are stored. Users with neither SHALL download anonymously without this check.
Scenario: Valid session
- WHEN a session exists and the server reports it as logged in
- THEN the download proceeds with that session and no re-login happens
Scenario: Anonymous user without stored credentials
- WHEN no session exists and no credentials are stored
- THEN no login-state request is sent and the download proceeds anonymously without a warning
Requirement: Expired login is renewed transparently
When the server reports the session as not logged in and credentials are stored, the plugin SHALL log in again and run the whole download with the new session.
Scenario: Session expired after inactivity
- WHEN the user downloads data more than one hour after the previous download within the same QGIS run
- THEN the plugin logs in again with the stored credentials and the download returns the same records as for a fresh login
Scenario: No session yet, credentials stored
- WHEN the first download after QGIS start is requested and credentials are stored
- THEN the plugin logs in and verifies that the new session is logged in before downloading
Requirement: Anonymous fallback is reported to the user
When the plugin expected to be logged in but cannot obtain a logged-in session, it SHALL show a warning in the QGIS message bar stating that the download runs anonymously and contains only records with access level A.
Scenario: Re-login fails
- WHEN the session has expired and logging in again with stored credentials fails
- THEN a warning appears in the message bar and the download continues anonymously
Scenario: Session expired and credentials removed
- WHEN an in-memory session has expired and no credentials are stored any more
- THEN a warning appears in the message bar and the download continues anonymously
Requirement: Failed state check does not block the download
If the login-state check cannot be completed (network error or a response that is not valid JSON), the plugin SHALL log a warning and proceed with the download using the current session.
Scenario: Login-state endpoint unreachable
- WHEN the login-state request fails with a network error
- THEN a warning is written to the log and the download is attempted as usual
Requirement: Removing stored credentials logs the user out
When the user removes the stored credentials, the plugin SHALL log the current session out on the server and discard it, so that later downloads run anonymously without restarting QGIS.
Scenario: Credentials removed while logged in
- WHEN the user removes the stored credentials while a logged-in session exists
- THEN the session is logged out on the server and the next download is anonymous without a warning
Scenario: Server unreachable during logout
- WHEN the logout request fails with a network error
- THEN the session is still discarded locally and the user is told the next download will be anonymous