nanxiuzi opened a new pull request, #18653:
URL: https://github.com/apache/dolphinscheduler/pull/18653

   <!--Thanks for contributing to Apache DolphinScheduler. Please review 
https://dolphinscheduler.apache.org/en-us/community/development/contribute.html 
before opening a pull request.-->
   
   ## Purpose of the pull request
   
   Closes #18652.
   
   The login session lifetime is hardcoded as `Constants.SESSION_TIME_OUT = 
7200`, so operators cannot adjust it without patching the source and 
rebuilding. This PR moves it into `ApiConfig` and exposes it as 
`api.session-timeout`.
   
   ## Brief change log
   
   - `dolphinscheduler-api/.../api/configuration/ApiConfig.java`
     - Add `Duration sessionTimeout` (default `2h`), validate that it is 
positive, and log it in `printConfig`.
   - `dolphinscheduler-api/.../api/service/impl/SessionServiceImpl.java`
     - `isSessionExpire` reads `apiConfig.getSessionTimeout()` instead of the 
constant.
   - `dolphinscheduler-common/.../common/constants/Constants.java`
     - Remove the now-unused `SESSION_TIME_OUT`.
   - `dolphinscheduler-api/src/main/resources/application.yaml`, 
`dolphinscheduler-standalone-server/src/main/resources/application.yaml`
     - Document `api.session-timeout`.
   - Tests: `SessionServiceTest` gains an `ApiConfig` spy plus a case covering 
the configured timeout; `LoginControllerTest` derives the expired timestamp 
from the config.
   - Docs (en / zh): add the `api.session-timeout` row.
   
   ## Root cause / motivation
   
   Two problems with the constant approach:
   
   1. It is a `static final int`, so it is **inlined** into 
`SessionServiceImpl` at compile time. Editing the constant alone has no effect 
— `dolphinscheduler-api` must be recompiled as well.
   2. It lives in `dolphinscheduler-common`, which is a jar shared by master / 
worker / alert / tools. Changing it forces all of those services to be replaced 
for what is purely an API-server concern.
   
   ## Behaviour
   
   Unchanged by default: the field defaults to 2 hours, so deployments that do 
not set the property keep the current behaviour exactly.
   
   Operators can now set, in `api-server/conf/application.yaml`:
   
   ```yaml
   api:
     session-timeout: 12h   # accepts a Duration, e.g. 30m, 2h, 1d
   ```
   
   ## Verify this change
   
   Unit tests pass:
   
   ```
   Tests run: 18, Failures: 0, Errors: 0, Skipped: 0
   ```
   
   The new case `SessionServiceTest#testIsSessionExpireUsesConfiguredTimeout` 
sets a 1-hour timeout and asserts a 30-minute-old session is alive while a 
90-minute-old one has expired. Verified end-to-end on a 3.4.2 deployment: 
setting `api.session-timeout: 12h` keeps a session alive past the previous 
2-hour limit, and the startup log shows the parsed value (`API config: 
sessionTimeout -> PT12H`).
   
   ## Pull Request Type
   
   - [ ] Bug fix (non-breaking change which fixes an issue)
   - [ ] New feature (non-breaking change which adds functionality)
   - [ ] Breaking change (fix or feature that would cause existing 
functionality to not work as expected)
   - [ ] Code refactoring
   - [x] Improvement (enhancement to an existing feature)
   - [x] Documentation update
   - [ ] Other (please describe):
   
   ## Does this pull request potentially affect one of the following parts
   
   - [ ] Dependencies (add or upgrade a dependency)
   - [ ] The public API
   - [ ] The core logic
   - [ ] The DSL
   - [ ] The RPC
   - [ ] The UI
   - [ ] The resources
   - [x] The documentation
   - [x] The configuration
   
   ## AI usage disclosure
   
   - [x] This contribution contains AI-generated code, and I have reviewed and 
tested it myself.
   - [ ] This contribution does not contain AI-generated code.
   
   ## Checklist
   
   - [x] *I have read the 
[CONTRIBUTING](https://github.com/apache/dolphinscheduler/blob/dev/CONTRIBUTING.md)
 doc*
   - [x] *I have added labels to this pull request*
   - [x] *I have added the appropriate milestone to this pull request*
   - [x] *I have associated a PR with an issue (required)*
   - [x] *I have read the [Code of 
Conduct](https://www.apache.org/foundation/policies/conduct)*


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to