- cleanupExpired() drops sessions expired by tokenTtl or sessionIdleTimeout and is
called opportunistically on issuing a token, bounding the session table; it is
protected and self-locking so subclasses can run it periodically
- issueToken() refuses a token already used by an active session instead of
silently merging two sessions (login replies 500 on a generator collision)
- document that the token generator must be collision-resistant
- tests: SessionCleanupOnLogin, ManualCleanup, TokenCollisionRejected
- parse the Basic auth-scheme case-insensitively (RFC 7235), matching Bearer
- register the http_server test only when pip_http_server and pip_http_client
targets exist, so TESTS=ON without the HTTP modules does not fail to link
- add a Basic_LowercaseScheme test
The idle timeout is opt-in: when set with setSessionIdleTimeout(), a session
expires after that period without a successful request and every successful
request extends it. When unset (the default), sessions are not touched and keep
the previous behavior: the absolute tokenTtl applied to created, or living until
logout. Both deadlines can be combined and the earlier one wins.
- SessionRec: add last_used, drop the unused refresh_token field
- checkToken(): update last_used only while the idle timeout is enabled
- tests: IdleTimeout, IdleActivityExtendsSession, IdleDisabledKeepsSession,
HasSessionIdleTimeout
The server no longer stores user accounts. PIHTTPServerMultiUser is renamed to
PIHTTPServerSessionAuth and keeps only the in-memory session table: credential
verification is delegated to the pure virtual checkCredentials(), implemented by
a client subclass that owns the user storage.
- remove UserRec, addUser/removeUser/userExists/userCount and the password
check callback; add protected revokeToken()/revokeUserTokens() helpers
- add configurable login/logout route paths (default /api/login, /api/logout)
- call checkCredentials() without holding the internal lock and report 500 when
the token generator yields no data
- rewrite tests around a client subclass with its own user table
- PIHTTPServerBasicAuth: parse Authorization: Basic header, validate credentials via callback
- PIHTTPServerProtected: wrap any handler with auth check (basic or custom token)
- Integration tests for both modules (12 test cases)
The operator<< / operator>> templates for MessageConst / MessageMutable
added in 4d8b7430 have no users in the tree (libs, tests, utils, main).
Drop them along with the pibinarystream.h include they required; the
binary-stream fallback static_assert in pibinarystream.h already gives a
clear compile error if external code ever streams an MQTT message.
Replace scattered option() calls, PIP_HAS_DEPS_* variables, and while-loop
resolver with pip_feature_flag() function and pip_resolve_feature_flags()
macro. Dependencies are declared inline and resolved in a single pass.
- CMake: drop PIP_HAS_SERIAL -> PIP_HAS_THREADS dependency and the forced
PIP_HAS_SERIAL=OFF for PICO_BOARD, so serial can be built on Pico
- piserial.cpp: guard termios/stty code (tcgetattr/tcsetattr/tcflush/tcdrain,
TIOCSBRK/TIOCCBRK, TIOCMBIS/TIOCMBIC/TIOCMGET, termios members, sys/ioctl.h
and termios.h includes) with PIP_HAS_TTY; O_NOCTTY replaced by
PISERIAL_NOCTTY (0 on no-TTY targets)
- add missing #ifndef fallbacks for B110..B115200 used by convertSpeed()
when termios.h is absent
- guard thread-only PIIODevice API calls (isThreadedRead/stopThreadedRead)
with PIP_HAS_THREADS in closeDevice/readDevice
- gate the availableDevicesInfo() test loop with PIP_HAS_FILESYSTEM||WINDOWS
(device enumeration is a filesystem feature)
- AGENTS.md: note that clang-format-18 is applied automatically on file edits
- use LFS64 file/stat APIs only on glibc/Windows (absent in musl)
- use plain sched_priority outside glibc
- do not declare pow10(double) where the system provides C23 pow10() (musl)
- ICU is off by default: modern ICU (>= 75) needs C++17 for its headers,
the project is built with C++11; enable explicitly with -DICU=ON
- fix latent crash: PIThread::setThreadName() read the thread handle from
inside the new thread; the handle is not guaranteed to be visible before
start (musl publishes it later), rename the calling thread via
pthread_self() instead
- drop INTROSPECTION conjunctions (CMake dep table already forces THREADS+SOCKET)
- remove whole-file guards in client_server/process tests (CMake only compiles them when flags are ON)
- normalize single-flag '#if defined(PIP_HAS_X)' to '#ifdef PIP_HAS_X'
Guard PIConnection, thread primitives, PICodeParser and other feature
code behind PIP_HAS_THREADS/PIP_HAS_FILESYSTEM. In CMake generate the
feature flags summary from the single PIP_HAS_FLAGS list (used by the
add_definitions loop as well), default ICU to OFF and make introspection
also require PIP_HAS_SOCKET. Build system/thread test suites only when
the corresponding feature flags are enabled.
Replace the ad-hoc if-blocks with a PIP_HAS_DEPS_<feature> dependency table
(analogous to __deps_* module dependencies in FindPIP.cmake) resolved to a
fixpoint. The table now also covers http_server (threads+socket) and fftw
(has_fft), and adds the hard client_server/cloud -> io_utils module
dependency. Restore client_server/cloud under the sodium_FOUND guard, put
-ftemplate-depth-32 back before the CMAKE_C_FLAGS copy, and fix the console
block indentation.