mirror of
https://github.com/ARUP-CAS/aiscr-qgis-amcr-viewer.git
synced 2026-10-09 20:37:37 +02:00
* fix: před stahováním ověřit přihlášení přes islogged Server při vypršelé session nevrací chybu, ale tiše odpoví jako anonymnímu uživateli (jen přístupnost A). Plugin proto před stahováním volá /api/user/islogged; při 'nologged' se jednou znovu přihlásí z uložených údajů, a když to nejde, varuje v liště, že stahuje anonymně. - amcr_tools: _check_islogged, _ensure_logged_in, volání v load_amcr_data - smoke test: 7 offline scénářů stavu přihlášení - README; changelog v2.2.0 v metadata.txt - openspec/changes/fix-session-expiry-islogged: návrh, spec, design, úkoly Closes #72. Připraveno s pomocí AI (Claude), ručně zkontrolováno. * feat: odebrání přihlašovacích údajů uživatele i odhlásí Dosud zůstala přihlášená session v paměti až do restartu QGIS, takže se po „Odebrat uložené přihlašovací údaje“ dál stahovalo jako přihlášený. Nově se session odhlásí na serveru (GET /api/user/logout) a zahodí; když server neodpoví, zahodí se aspoň lokálně. - amcr_tools: logout_from_api; amcr_dialog: volání v _forget_credentials - smoke test: odhlášení, chyba sítě, bez session - README, changelog v2.2.0, OpenSpec (požadavek + úkoly 2b; 3.3 ověřeno) Připraveno s pomocí AI (Claude), ručně zkontrolováno. * chore: archivovat OpenSpec změnu fix-session-expiry-islogged Všechny úkoly hotové (2b.2 – odhlášení – ověřeno ručně v QGIS), archivováno s --skip-specs (stupeň change-tracked, bez openspec/specs/). Připraveno s pomocí AI (Claude), ručně zkontrolováno.
2.7 KiB
2.7 KiB
Proposal
Why
Login to digiarchiv expires after 1 h of inactivity (sessionTimeout: 3600)
and the server then silently treats the request as anonymous: HTTP 200, no
error, only pristupnost=A data. The plugin detects expiry only by HTTP 401
or error text, which never arrives, so a logged-in user who downloads again
after a pause gets incomplete data without any warning (issue #72, verified
manually in QGIS and against the live API).
What Changes
- Before each download the plugin checks the login state with
GET /api/user/isloggedwhenever the user is (or should be) logged in – i.e. an in-memory session exists or credentials are stored. - When the server answers
{"error": "nologged"}and credentials are stored, the plugin logs in again and continues the download with the new session. - When the re-login fails (or credentials are missing), the plugin warns in the QGIS message bar that the download runs anonymously and returns only records with access level A – not only in the log.
- Removing the stored credentials (Odebrat uložené přihlašovací údaje)
also logs the session out on the server (
GET /api/user/logout) and drops it from memory; today it stays logged in until QGIS restarts. - When the check itself cannot be completed (network error, invalid JSON), the download is not blocked; the plugin logs a warning and proceeds.
- The existing error-text based detection (
_is_auth_error) stays as a fallback; it is documented as not triggered by the current server. - Version bump + changelog (
metadata.txt,CITATION.cff).
Out of scope:
- Keeping the session alive in the background (polling
isloggeddoes not extend it anyway). - Showing the user's access level in the UI (
islogged?wantsUser=true). - Codelist updates:
amcr_codelistscalls the API with plainrequestswithout the session, so login state does not affect them today.
Capabilities
New Capabilities
amcr-session: login session against digiarchiv – validating the session before a download, transparent re-login and informing the user when data are downloaded anonymously.
Modified Capabilities
Impact
- Code:
amcr_viewer/amcr_dialog.py(logout when credentials are removed);amcr_viewer/amcr_tools.py(logout helper, new login-state check, call at the start ofload_amcr_data, message bar warning);tests/smoke_test.py(offline test of the check with a mocked HTTP session). - API: one extra
GET /api/user/isloggedper download, only when the user is logged in or has stored credentials; anonymous users are unaffected. - No new dependencies; Qt5/Qt6 compatibility rules from
AGENTS.mdapply.