Exercise 3: A Real delete() Method, Verified Against the Database Itself — Possible Solution ==================================================================== THE METHOD AND THE LOGOUT HANDLER ------------------------------ class SqliteSessionStore: ... def delete(self, sid): self.conn.execute('DELETE FROM sessions WHERE id = ?', (sid,)) self.conn.commit() def load(self, sid): row = SessionRow.get(self.conn, sid) if row is None: return None if time.time() - row.created_at > self.max_age: self.delete(sid) # reused directly, instead of duplicating the DELETE return None return json.loads(row.data) def logout_handler(request): request.state['logged_out'] = True sid = request.cookies.get('session_id') # already available on Request since Chapter 6 if sid: store.delete(sid) response = Response("logged out") response.delete_cookie('session_id') # Chapter 6's own real cookie-clearing method return response VERIFIED, REAL RESULT ------------------------------ store = SqliteSessionStore(db_path) sid = store.create() store.save(sid, {'visits': 1}) print(store.load(sid)) # {'visits': 1} row_count = store.conn.execute('SELECT COUNT(*) FROM sessions').fetchone()[0] print(row_count) # 1 store.delete(sid) # what the real logout_handler above calls row_count = store.conn.execute('SELECT COUNT(*) FROM sessions').fetchone()[0] print(row_count) # 0 print(store.load(sid)) # None WHY THIS WORKS AS AN ANSWER ------------------------------ It verifies the real row count in the sessions table directly, via a genuine SELECT COUNT(*) query against the database itself, both before and after calling delete() - not just checking that load() returns None afterward, which a cookie-only fix (Chapter 6's own delete_cookie() alone, with no server-side change at all) could already produce by making the client simply stop sending the session ID. The row count going from a real 1 down to a real 0 proves the session's own data genuinely left the database, closing the real gap Chapter 6's own logout exercise left open: clearing a cookie stops one client from using a session, but does nothing on its own to remove the actual session data sitting on the server.