Files
aiscr-qgis-amcr-viewer/openspec/changes/archive/2026-10-02-fix-session-expiry-islogged/tasks.md
T
david-spacil 74090a80c6 fix: před stahováním ověřit přihlášení přes islogged (#72) (#80)
* fix: před stahováním ověřit přihlášení přes islogged

Server při vypršelé session nevrací chybu, ale tiše odpoví jako
anonymnímu uživateli (jen přístupnost A). Plugin proto před stahováním
volá /api/user/islogged; při 'nologged' se jednou znovu přihlásí
z uložených údajů, a když to nejde, varuje v liště, že stahuje anonymně.

- amcr_tools: _check_islogged, _ensure_logged_in, volání v load_amcr_data
- smoke test: 7 offline scénářů stavu přihlášení
- README; changelog v2.2.0 v metadata.txt
- openspec/changes/fix-session-expiry-islogged: návrh, spec, design, úkoly

Closes #72. Připraveno s pomocí AI (Claude), ručně zkontrolováno.

* feat: odebrání přihlašovacích údajů uživatele i odhlásí

Dosud zůstala přihlášená session v paměti až do restartu QGIS, takže
se po „Odebrat uložené přihlašovací údaje“ dál stahovalo jako přihlášený.
Nově se session odhlásí na serveru (GET /api/user/logout) a zahodí;
když server neodpoví, zahodí se aspoň lokálně.

- amcr_tools: logout_from_api; amcr_dialog: volání v _forget_credentials
- smoke test: odhlášení, chyba sítě, bez session
- README, changelog v2.2.0, OpenSpec (požadavek + úkoly 2b; 3.3 ověřeno)

Připraveno s pomocí AI (Claude), ručně zkontrolováno.

* chore: archivovat OpenSpec změnu fix-session-expiry-islogged

Všechny úkoly hotové (2b.2 – odhlášení – ověřeno ručně v QGIS),
archivováno s --skip-specs (stupeň change-tracked, bez openspec/specs/).

Připraveno s pomocí AI (Claude), ručně zkontrolováno.
2026-10-02 12:37:31 +02:00

2.7 KiB

Tasks

1. Login-state check

  • 1.1 Add _ensure_logged_in() to amcr_viewer/amcr_tools.py per design.md (statuses anonymous / logged_in / relogged / fallback / unknown, GET /api/user/islogged with the current session, one re-login on nologged); verify with python3 tests/check_sources.py and ruff check .
  • 1.2 Add a comment to _is_auth_error that the current server never returns such an error on expiry and the check is kept as a fallback; verify by reading the diff
  • 1.3 Extend tests/smoke_test.py with offline cases using a fake session object (valid session, nologged + successful re-login, nologged + failed re-login, no credentials, network error); verify the smoke test passes in qgis/qgis:ltr and qgis/qgis:stable

2. Integration into the download

  • 2.1 Call _ensure_logged_in() in load_amcr_data after the re-entrancy guard, before the first query; on fallback push a message bar warning (Czech, scoped Qgis.MessageLevel.Warning) that the download runs anonymously and contains only access level A; verify by smoke test and code review
  • 2.2 Live check without credentials: anonymous download path sends no islogged request and a made-up JSESSIONID yields nologged (curl / probe script in scratch); verify outputs recorded in the PR
  • 2.3 Update README.md if it describes login/session behaviour; verify the text matches the new behaviour (or note that nothing needed changing)

2b. Logout when credentials are removed

  • 2b.1 Add logout_from_api() to amcr_tools.py and call it from LoginDialog._forget_credentials; extend the smoke test (session logged out + dropped, network error still drops it, no session = no request); update README and changelog; verify smoke test ltr + stable
  • 2b.2 Manual test in QGIS: log in, download, remove the stored credentials, download again; verify the log shows "Uživatel odhlášen" and the count drops to the anonymous one

3. Release preparation and verification

  • 3.1 Add changelog entries under v2.2.0 in amcr_viewer/metadata.txt (the fix ships with 2.2.0; CITATION.cff already says 2.2.0 and date-released moves on release day); verify both versions match
  • 3.2 Run the full local check set from AGENTS.md (check_sources, bandit, detect-secrets --all-files, flake8 --isolated, ruff, pyqgis4-checker log empty, smoke test ltr + stable); verify all clean
  • 3.3 Manual test in QGIS with a researcher account: download SN for whole CZ, simulate expiry in the Python console with amcr_tools.AMCR_SESSION.get("https://digiarchiv.aiscr.cz/api/user/logout"), download again; verify log shows re-login and the count matches the logged-in count (not the anonymous one)