"""Periodic sweep of expired auth_sessions rows. get_current_user (app/deps.py) already rejects expired sessions on read, but never deletes them — left alone, auth_sessions grows forever. The lifespan in app/main.py runs delete_expired_sessions on a timer to keep the table bounded. """ from datetime import datetime, timezone from sqlalchemy import delete from sqlalchemy.ext.asyncio import AsyncSession from app.models.auth_session import AuthSession async def delete_expired_sessions(db: AsyncSession) -> int: """Deletes expired auth_sessions rows. Returns the number deleted.""" result = await db.execute( delete(AuthSession).where(AuthSession.expires_at < datetime.now(timezone.utc)) ) await db.commit() return result.rowcount