Derafu: Session
The wiring of the session and of the flash messages of Mezzio, with the session of PHP, for applications that use symfony/dependency-injection. It has no PHP code: it is a configuration file with the middlewares and the environment variables that configure the cookie.
derafu/foundation imports it, so a site does not do anything else. derafu/http reads the session and the flash messages of the request ($request->session() and $request->flash()), derafu/csrf keeps its tokens in the session, and derafu/auth keeps the user in it; this package is what puts them there.
Install
composer require derafu/session
Import the services and put the middlewares in the pipeline, after the router and before whatever uses the session:
imports:
- { resource: '../vendor/derafu/session/resources/config/session-services.yaml' }
services:
Psr\Http\Server\RequestHandlerInterface:
class: Derafu\Http\Service\RequestHandler
arguments:
$middlewares:
- '@Derafu\Http\Middleware\RouterMiddleware'
- '@Mezzio\Session\SessionMiddleware'
- '@Mezzio\Flash\FlashMessageMiddleware'
# ...
Variables
The session is the one of PHP, and its cookie is secure by default:
| Variable | Type | Default | Description |
|---|---|---|---|
SESSION_NAME |
string | DERAFU_SESSION |
Name of the cookie. |
SESSION_LIFETIME_SECONDS |
int | 3600 |
Seconds of life of the cookie. |
SESSION_COOKIE_PATH |
string | / |
Path of the cookie. |
SESSION_COOKIE_DOMAIN |
string | empty | Domain of the cookie: empty is the host that set it, without its subdomains. |
SESSION_COOKIE_SECURE |
bool | true |
The cookie is sent only by HTTPS. In development over HTTP set it to false. |
SESSION_COOKIE_HTTP_ONLY |
bool | true |
The cookie is not readable by JavaScript. |
SESSION_COOKIE_SAMESITE |
string | Lax |
SameSite of the cookie: Lax keeps it from going in a POST from another site. |
SESSION_CACHE_LIMITER |
string | nocache |
Cache limiter of PHP. |
SESSION_CACHE_EXPIRE_MINUTES |
int | 180 |
Cache expire of PHP, in minutes. |
The defaults are declared as strings, which is what Symfony asks of the default of an environment variable.
What a request does
The session of a visitor is created when something is written in it, and not before: a visitor that only reads pages that do not use the session does not get a cookie. A session that did not change does not set the cookie again.