Anybody know how/if it's possible to read session ...
# lucee
s
Anybody know how/if it's possible to read session data from a database backed session cache back into native session structs? The data appears to be stored as a binary encoded string.
I am trying to figure out how to invalidate all active sessions for a given session.memberID
b
Is the real question how to take the raw serialized data stored as a string directly in the DB and deserialize it manually outside of Lucee?
s
Yep
deserialize it with Lucee I guess
b
This isn't necessarily straightforward, but if Lucee stores its data in a DB the same way it stores it in most caches, you'd need to start by passing it to
evaluate()
which should give you an instance of a Java object, which would have your session data inside
Note, Lucee could change how it serializes session data at any time and your process may break
Lucee generally wraps your session data in a java object and passes it to
serialize()
s
If I do cacheget() to get a session based on a key I know, the result is a native array, like:
If I pass that into evaluate() I get an error. Message Syntax Error, Invalid Construct Detail at position 1 in [��sr@lucee.common ...]
This might have to do with the fact I am using the MongoDBCache extension as the session store...
b
ahh, well that could change everything, lol
Ortus' mongoDB cache or LAS's?
s
LAS's
b
The value may be base64 encoded
Try putting it through
toBinary()
first
s
The MonboDB cache entry uses org.lucee.mongodb.util.SerializerUtil to serialize the data before writing to the DB
Yeah, looking at that now
Seems some
lucee.runtime.converter.JavaConverter
class is at play
Looks like it base64 decodes and then passes the byte array stream to a
ObjectInputStreamImpl
instance, then calls
readObject()
s
I tried:
Copy code
serializerUtil = createobject("java","org.lucee.mongodb.util.SerializerUtil");
dump(var=serializerUtil.evaluate(sessions.first().data), abort=true);
b
Seems his class is to override how classloading is done
s
And get this
even less helpful 🤣
b
Interesting, that may be correct though
There maybe serialized objects inside of it
inception
s
right. just have to figure out how to deserialize?
There's an extra level going on there-- what is
dbObject
an instance of and where does it come from
s
It's MongoDB's native object - it's basically an ordered struct
s
I guess what I mean is it's the MongoDB java driver's native object
b
It's a native array of byte arrays
which may ultimately represent a native MongoDB object, but more deserialization would be in order
s
Yeah, right now I am trying to see if I can manually create a MongoDBCacheDocument object with a document from the database.
z
one of the issues with cache providers is that they need to be able to deserialize any class which gets stored in a session, so the various cache providers need to be aware of the osgi classloaders, we had that problem with ehcache recently, the ehcache provider wasn't able to deserialize postgres objects stored in the session
s
Can anyone point me in the Lucee codebase where session deserialization occurs with cache based sessions? I feel like I'm getting the correct result from
cacheGet()
and
MongoDBCacheEntry.getValue()
(they are the same) - I just don't understand what Lucee then does to convert/append that
Native Array byte[][]
value to the session scope.
b
@seandaniels The serialization/deserialization of objects is not handled by the Lucee core, so no such code exists to show you.
Each cache provider decides how they wish to serialize objects for their backend storage
s
That makes sense. But I would expect there has to be some sort of common interface since any cache type can be used for session storage? I just don't understand why the cacheGet() for my session storage object comes back as this unusable native byte array. Or, I'm sure not unusable, just don't know how to get it into a usable state.
I just don't have the java skills to get at this I guess