Derafu: Session

GitHub GitHub last commit CI Workflow Total Downloads

The wiring of the session and of the flash messages of Mezzio, with the session of PHP, for applications that use symfony/dependency-injection. It has no PHP code: it is a configuration file with the middlewares and the environment variables that configure the cookie.

derafu/foundation imports it, so a site does not do anything else. derafu/http reads the session and the flash messages of the request ($request->session() and $request->flash()), derafu/csrf keeps its tokens in the session, and derafu/auth keeps the user in it; this package is what puts them there.

Install

composer require derafu/session

Import the services and put the middlewares in the pipeline, after the router and before whatever uses the session:

imports:
    - { resource: '../vendor/derafu/session/resources/config/session-services.yaml' }

services:
    Psr\Http\Server\RequestHandlerInterface:
        class: Derafu\Http\Service\RequestHandler
        arguments:
            $middlewares:
                - '@Derafu\Http\Middleware\RouterMiddleware'
                - '@Mezzio\Session\SessionMiddleware'
                - '@Mezzio\Flash\FlashMessageMiddleware'
                # ...

Variables

The session is the one of PHP, and its cookie is secure by default:

Variable Type Default Description
SESSION_NAME string DERAFU_SESSION Name of the cookie.
SESSION_LIFETIME_SECONDS int 3600 Seconds of life of the cookie.
SESSION_COOKIE_PATH string / Path of the cookie.
SESSION_COOKIE_DOMAIN string empty Domain of the cookie: empty is the host that set it, without its subdomains.
SESSION_COOKIE_SECURE bool true The cookie is sent only by HTTPS. In development over HTTP set it to false.
SESSION_COOKIE_HTTP_ONLY bool true The cookie is not readable by JavaScript.
SESSION_COOKIE_SAMESITE string Lax SameSite of the cookie: Lax keeps it from going in a POST from another site.
SESSION_CACHE_LIMITER string nocache Cache limiter of PHP.
SESSION_CACHE_EXPIRE_MINUTES int 180 Cache expire of PHP, in minutes.

The defaults are declared as strings, which is what Symfony asks of the default of an environment variable.

What a request does

The session of a visitor is created when something is written in it, and not before: a visitor that only reads pages that do not use the session does not get a cookie. A session that did not change does not set the cookie again.

On this page

Last updated on 08/10/2026 by Anonymous