Skip to content

feat(query): SHOW/TERMINATE SESSIONS - #1814

Draft
katarinasupe wants to merge 2 commits into
release/3.14from
docs/session-user-read-uaf
Draft

katarinasupe wants to merge 2 commits into
release/3.14from
docs/session-user-read-uaf

Conversation

@katarinasupe

@katarinasupe katarinasupe commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Description

Documents SHOW SESSIONS and TERMINATE SESSIONS on the Transactions page and in the query privileges table. Also fixes two older statements on the same page: TERMINATE TRANSACTIONS $id (parameters were never accepted) and the new database column of SHOW TRANSACTIONS (memgraph/memgraph#4571).

Not done:

  • SHOW TRANSACTIONS example outputs still show seven columns; I don't know what database shows on snapshot and GC rows.
  • SHOW ACTIVE USERS also gained columns in #4571 (server-stats page).

Product PR

memgraph/memgraph#4577

Checklist

  • For a product change: milestone set to the release and feature or bugfix label added
  • For a product change: this PR is linked from the product PR's documentation checklist

@katarinasupe katarinasupe added this to the 3.14 milestone Oct 7, 2026
@katarinasupe katarinasupe added the feature Documentation related to a new product feature of feature update label Oct 7, 2026
@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
documentation Ready Ready Preview Oct 7, 2026 11:52am UTC

Request Review

@andrejtonev andrejtonev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for writing this up! I checked every statement against current master (6e9c79da3), on a live instance as well as in the code. Most of it is accurate. The inline comments cover two statements that are wrong for 3.14 (SESSIONS isn't reserved, and the forced-DROP DATABASE example no longer applies after #4843), a few that overstate what happens (killed: true, "running query is aborted"), and some behaviour that's missing: open-transaction rollback, what the client sees and driver retries, auth disabled, Community vs Enterprise, impersonation, coordinators, LOGOFF and $id parameters. Every suggestion was re-run against master.

Three things outside this diff:

  1. TERMINATE TRANSACTIONS $id (around line 340): "A parameterized id is treated exactly like a literal one, so running TERMINATE TRANSACTIONS $id with $id = "*" also terminates everything." This has never worked. The grammar only accepts a literal there (transactionId : literal, unchanged since the query was added), so TERMINATE TRANSACTIONS $id is a syntax error (extraneous input '$' expecting ...) whatever $id is. The sentence came in with v3.13 (#1689). Suggested replacement: "Transaction ids, including "*", must be string literals. Query parameters such as $id aren't supported and cause a syntax error."
  2. SHOW TRANSACTIONS columns (line 95): since memgraph#4571 (3.14, listed under breaking changes in #1764), SHOW TRANSACTIONS returns an 8th column, database, after elapsed_ms. The page still says "contains seven columns", and the column table and example outputs don't include it. Suggested row: | database | String | The database the transaction is running on. |
  3. PR description: it says the SHOW TRANSACTIONS fix is internal and "the release note already covers it". It doesn't: on release/3.14 the only #4577 entry is the feature line. I've suggested a bug-fix line on #1764.

Comment thread pages/fundamentals/transactions.mdx
Comment thread pages/fundamentals/transactions.mdx Outdated
Comment thread pages/fundamentals/transactions.mdx Outdated
Comment thread pages/fundamentals/transactions.mdx Outdated
Comment thread pages/fundamentals/transactions.mdx Outdated
Comment thread pages/fundamentals/transactions.mdx Outdated
Comment thread pages/fundamentals/transactions.mdx
Comment thread pages/fundamentals/transactions.mdx
Comment thread pages/fundamentals/transactions.mdx Outdated
Comment thread pages/database-management/authentication-and-authorization/query-privileges.mdx Outdated
@andrejtonev andrejtonev mentioned this pull request Oct 7, 2026
77 of 87 tasks
katarinasupe and others added 2 commits October 7, 2026 13:48
Documents the session management queries from memgraph/memgraph#4577:
listing open Bolt sessions and terminating them from another connection,
who can see and terminate which sessions, the result columns, and the
SESSIONS reserved keyword. Adds both queries to the query privileges table.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Also fix the TERMINATE TRANSACTIONS parameter claim and add the database
column of SHOW TRANSACTIONS.
| `SHOW TRANSACTIONS` | `TRANSACTION_MANAGEMENT` | `SHOW TRANSACTIONS` |
| `TERMINATE TRANSACTIONS` | `TRANSACTION_MANAGEMENT` | `TERMINATE TRANSACTIONS 'transaction_id'` |
| `TERMINATE TRANSACTIONS "*"` | `TRANSACTION_MANAGEMENT` | `TERMINATE TRANSACTIONS "*"` terminates every transaction the user may terminate. Without the privilege, only the user's own transactions are terminated. |
| `SHOW SESSIONS` | **None** | `SHOW SESSIONS` lists the user's own sessions. With `TRANSACTION_MANAGEMENT`, it also lists other users' sessions on the databases where the user has the privilege. |

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
| `SHOW SESSIONS` | **None** | `SHOW SESSIONS` lists the user's own sessions. With `TRANSACTION_MANAGEMENT`, it also lists other users' sessions on the databases where the user has the privilege. |
| `SHOW SESSIONS` | **None** | `SHOW SESSIONS` lists the user's own sessions. With `TRANSACTION_MANAGEMENT` privilege, it also lists other users' sessions on the databases where the user has the privilege. |

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In general, for me to be able to understand what this sentence was trying to convey, I had to go to /database-management/authentication-and-authorization/role-based-access-control to understand what does "With 'TRANSACTION_MANAGEMENT'" even mean.

This is maybe a comment for a wider revamp, but here it helped to even mention this is a privilege of some kind.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe the suggestion I'm trying to make is to add a descriptive noun when mentioning a part of the code

'this()' function
'THIS' clause
'THIS' privilege
'--this' flag

A session is one client connection to Memgraph over Bolt. You can list the
open sessions and close any of them from another connection, for example an
idle (often pooled) connection that still has a database selected and makes
[`DROP DATABASE`](/database-management/multi-tenancy#drop-database-with-force)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
[`DROP DATABASE`](/database-management/multi-tenancy#drop-database-with-force)
[`DROP DATABASE`](/database-management/multi-tenancy#drop-database-with-force) query

open sessions and close any of them from another connection, for example an
idle (often pooled) connection that still has a database selected and makes
[`DROP DATABASE`](/database-management/multi-tenancy#drop-database-with-force)
fail with `Cannot delete <name>, it is currently being used.` Available since

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
fail with `Cannot delete <name>, it is currently being used.` Available since
fail with `Cannot delete <name>, it is currently being used.` error message. Available since


Session queries run on data instances (MAIN and REPLICA), and each instance
lists and closes only the sessions connected to it. On a high availability
coordinator they fail with `Coordinator can run only coordinator queries!`.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
coordinator they fail with `Coordinator can run only coordinator queries!`.
coordinator they fail with `Coordinator can run only coordinator queries!` error message.

Comment on lines +455 to +456
They run as implicit transactions only; running them inside an explicit
transaction raises an error.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the old days, I would've changed this to "...only, so running them..." or even better "..., so don't run them inside explicit transactions (such as: ...) "

What are explicit transactions? bo - might be good to have an example, explanation?


| Column | Type | Description |
|---|---|---|
| `session_id` | `String` | Unique id of the session. Use this value with `TERMINATE SESSIONS`. |

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"'TERMINATE SESSIONS' query to terminate it"?

| `database` | `String` | The database the session is using, or `""` if it isn't using one. |
| `login_timestamp` | `String` | UTC time of the session's most recent login, formatted as `YYYY-MM-DD HH:MM:SS.ffffff` (no time zone suffix). |

You see your own sessions, and the sessions on every database where you have

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
You see your own sessions, and the sessions on every database where you have
Running the 'SHOW SESSION;' query will show your own sessions, and the sessions on every database where you have

a connection counts as the impersonated user, and its queries are checked
against that user's privileges.

In the following example, `admin` has `TRANSACTION_MANAGEMENT` on every

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
In the following example, `admin` has `TRANSACTION_MANAGEMENT` on every
In the following example, `admin` has `TRANSACTION_MANAGEMENT` privilege on every


In the following example, `admin` has `TRANSACTION_MANAGEMENT` on every
database, and `alice` has two idle connections open, one on `analytics` and
one on `memgraph`. The session running the query is listed too:

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
one on `memgraph`. The session running the query is listed too:
one on `memgraph` database. The session running the query is listed too:

TERMINATE SESSIONS 'SESSION_ID' [, 'SESSION_ID' ...];
```

`SESSION_ID` is a `session_id` from `SHOW SESSIONS`, written as a string

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
`SESSION_ID` is a `session_id` from `SHOW SESSIONS`, written as a string
`SESSION_ID` is a `session_id` from `SHOW SESSIONS` output, written as a string

Comment on lines +515 to +523
An idle session is closed immediately. For a session that is running a query,
Memgraph aborts its transaction and closes the connection as soon as that
query returns. Most queries stop right away, but one that doesn't check for
termination (for example, a long-running function call) runs until it
finishes, and its transaction is then not committed. If the session has an
open explicit transaction (it ran `BEGIN` but hasn't committed), that
transaction is rolled back: its uncommitted changes are discarded and any
writes it holds are released, so conflicting transactions can proceed. A
transaction that is already committing isn't interrupted; it completes.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is very hard for me to grasp all the information it's trying to convey. I would need a bullet point list. This makes it easier to understand what IF IF ELSE structure is happening here

When I'm reading this block of text I'm unsure where one scenario ends and another one ends

The termination of the session depends on the session type:

  • Idle session - closes immediately
  • Session running a query - Memgraph will abort transactions and close the session (why connection?) as soon as the query returns. If the query doesn't check for termination (like, for example, a long-running function call), the transaction will not be committed once it finishes running.
  • Session with an open explicit transaction - If SOMETHING SOMETHING happened (description of an explicit transaction) the transaction is rolled back and uncommitted changes are discarded. If the transaction is already committing, it isn't interrupted and it can complete committing.

@vpavicic vpavicic Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I also feel like this paragraph, and the two after it require some kind of subtitle or intro... so this is describing the termination behavior based on session type

below is Client behavior upon session termination

and i guess i would first explain how to terminate all kinds of sessions, mine or other ppls, then explain behaviour?

This branch was successfully deployed

1 active deployment
Preview — 54ce8128 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

feature Documentation related to a new product feature of feature update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants