diff --git a/packages/application/auth/login_use_case.py b/packages/application/auth/login_use_case.py old mode 100644 new mode 100755 index 15b9d263c..2cf852ad1 --- a/packages/application/auth/login_use_case.py +++ b/packages/application/auth/login_use_case.py @@ -248,20 +248,16 @@ class RefreshTokenUseCase: """ 通过 refresh_token 查找 session - 遍历所有 session 查找匹配的 refresh_token(生产环境应使用索引优化) + 使用 Redis 中的反向索引 (refresh_token -> session_id) 快速查找 session。 + 反向索引在 save_session 时创建,确保了 O(1) 的查找复杂度。 + + Args: + refresh_token: 刷新令牌 + + Returns: + Session 数据字典,包含 session_id, user_id 等信息;如果不存在返回 None """ - # Scan Redis for all session keys and check refresh_token - # This is a simplified implementation - in production, use a reverse index - # e.g., store refresh_token -> session_id mapping in Redis - - # For now, iterate through user sessions - # In a real implementation, you would maintain a reverse index: - # refresh_token:session_id -> session_id - # or use Redis SCAN to find sessions with matching refresh_token - - # Simplified: iterate users (not scalable for production) - # In production, add: session_store.save_refresh_token_index(refresh_token, session_id) - return None # Placeholder - implement with reverse index in production + return self.session_store.get_session_by_refresh_token(refresh_token) class LogoutRequest: