Download the PHP package phpdot/session without Composer
On this page you can find all versions of the php package phpdot/session. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Informations about the package session
phpdot/session
Secure session management for PSR-15 applications: pluggable storage handlers (file, Redis, array,
null), one-request flash data, CSRF tokens, and a middleware that starts the session and writes the
cookie around each request. The session implements PHPdot\Contracts\Session\SessionInterface, so
consumers depend on the contract, not the implementation.
Table of Contents
- Requirements
- Installation
- Usage
- Architecture
- Testing
- License
Requirements
| Requirement | Constraint |
|---|---|
| PHP | >= 8.5 |
phpdot/contracts |
^0.2 |
psr/http-message |
^2.0 |
psr/http-server-handler |
^1.0 |
psr/http-server-middleware |
^1.0 |
ext-redis is suggested (only for the Redis handler); phpdot/container is a dev-only suggestion for
the binding attributes.
Installation
Usage
Three objects and one middleware:
Data and flash
CSRF and lifecycle
The session issues and verifies CSRF tokens, and supports invalidate() (new id, keep data),
destroy(), and lifetime expiry — all driven through SessionManager.
Handlers
FileHandler (filesystem), RedisHandler (ext-redis, TTL-based expiry), ArrayHandler (in-memory, for
tests), and NullHandler all implement PHPdot\Contracts\Session\SessionHandlerInterface; JsonSerializer
and PhpSerializer handle payload encoding. Any of them is a drop-in.
FileHandler creates its directory 0700 and session files 0600 — session files hold authenticated
identity, so nothing is ever group- or world-readable, including under the default savePath in the
shared /tmp. On multi-user hosts prefer a directory owned by the application user anyway.
Architecture
SessionMiddleware resolves the session for the request through SessionManager, which loads and saves
the payload via the configured handler and serializer. On the way out it writes the session cookie
(honouring the SessionConfig flags). Flash data and CSRF live in the Session value itself.
Testing
License
MIT.
This repository is a read-only mirror, generated by CI from phpdot/monorepo. Pull requests and issues belong in the monorepo.
All versions of session with dependencies
phpdot/contracts Version ^0.3
psr/http-message Version ^2.0
psr/http-server-handler Version ^1.0
psr/http-server-middleware Version ^1.0