Download the PHP package popphp/pop-session without Composer
On this page you can find all versions of the php package popphp/pop-session. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Informations about the package pop-session
pop-session
- Overview
- Install
- Quickstart
- Session ID and Regeneration
- Counting and Iterating
- Time-Based
- Request-Based
- Namespaces
- Advanced Usage
Overview
pop-session is a component used to manage sessions and session data in the PHP web environment.
It includes the ability to also manage namespaces within the session as well as timed-based and
request-based expirations.
pop-session is a component of the Pop PHP Framework.
Top
Install
Install pop-session using Composer.
composer require popphp/pop-session
Or, require it in your composer.json file
"require": {
"popphp/pop-session" : "^5.0.0"
}
Top
Quickstart
You can create a session and store and fetch data from it:
You can unset session data like this:
And finally, you can destroy the whole session like this:
Top
Session ID and Regeneration
You can get the current session's ID and name, and regenerate the ID (for example, after a user logs in, to guard against session fixation):
Top
Counting and Iterating
Session and SessionNamespace are both Countable and IteratorAggregate, so you can
count and loop over session data directly, or get it as a plain array with toArray():
Top
Time-Based
Session values can be made available based on time expiration:
Then, the next request will be successful if it's within the time limit of that session data:
Top
Request-Based
Session values can be made available based on number of requests:
Then, the next request will be successful if it's within the set limit of number requests allowed before that session data is expired:
Top
Namespaces
You can store session data under a namespace to separate that data from the global session data:
Session namespaces can also store time-based and request-based session data:
You can destroy just the namespace's data, or pass true to destroy the entire underlying
session, not just this namespace:
Top
Advanced Usage
Session::getInstance() accepts an optional array of options. These are only applied the
first time it's called in a given request - later calls in that same request ignore
$options, unless preceded by kill():
lifetime- cookie lifetime in seconds (default: yourphp.inivalue)path- cookie path (default: yourphp.inivalue)domain- cookie domain (default: yourphp.inivalue)secure- cookie secure flag (default: yourphp.inivalue)httponly- cookie HttpOnly flag (default:true)samesite- cookie SameSite attribute (default: yourphp.inivalue, or'Lax'if unset)strict_mode- PHP'ssession.use_strict_modefixation defense (default:true)
You can manually trigger a check of time-based and request-based session values (removing
any that have expired or exceeded their hop limit) at any point by calling sweep(). This is
also available on SessionNamespace:
If you need to release the session's write lock early, without ending the session, call
close():
You can plug in a custom \SessionHandlerInterface (for example, to store sessions in Redis
or a database) with setHandler(). It must be called before the first Session::getInstance()
call:
Session and SessionNamespace also implement JsonSerializable, so you can pass either
directly to json_encode():
Top