---
title: "Introduction"
description: "The services of the session and of the flash messages of Mezzio, configured with environment variables"
type: "docs"
category: "doc"
tags: []
authors: [Anonymous]
date: "2026-10-08"
last_update: "2026-10-08"
time_minutes: 3
draft: false
unlisted: false
url: "https://www.derafu.dev/docs/core/session/introduction"
---

# Derafu: Session

[![GitHub](https://img.shields.io/badge/github-derafu%2Fsession-blue?logo=github)](https://github.com/derafu/session)
![GitHub last commit](https://img.shields.io/github/last-commit/derafu/session/main)
![CI Workflow](https://github.com/derafu/session/actions/workflows/ci.yml/badge.svg?branch=main&event=push)
![Total Downloads](https://poser.pugx.org/derafu/session/downloads)

The wiring of the session and of the flash messages of [Mezzio](https://docs.mezzio.dev/mezzio-session/), with the session of PHP, for applications that use `symfony/dependency-injection`. It has no PHP code: it is a configuration file with the middlewares and the environment variables that configure the cookie.

[`derafu/foundation`](https://www.derafu.dev/docs/core/foundation) imports it, so a site does not do anything else. [`derafu/http`](https://www.derafu.dev/docs/core/http) reads the session and the flash messages of the request (`$request->session()` and `$request->flash()`), [`derafu/csrf`](https://www.derafu.dev/docs/core/csrf) keeps its tokens in the session, and [`derafu/auth`](https://www.derafu.dev/docs/core/auth) keeps the user in it; this package is what puts them there.

## Install

```bash
composer require derafu/session
```

Import the services and put the middlewares in the pipeline, after the router and before whatever uses the session:

```yaml
imports:
    - { resource: '../vendor/derafu/session/resources/config/session-services.yaml' }

services:
    Psr\Http\Server\RequestHandlerInterface:
        class: Derafu\Http\Service\RequestHandler
        arguments:
            $middlewares:
                - '@Derafu\Http\Middleware\RouterMiddleware'
                - '@Mezzio\Session\SessionMiddleware'
                - '@Mezzio\Flash\FlashMessageMiddleware'
                # ...
```

## Variables

The session is the one of PHP, and its cookie is secure by default:

| Variable | Type | Default | Description |
| --- | --- | --- | --- |
| `SESSION_NAME` | string | `DERAFU_SESSION` | Name of the cookie. |
| `SESSION_LIFETIME_SECONDS` | int | `3600` | Seconds of life of the cookie. |
| `SESSION_COOKIE_PATH` | string | `/` | Path of the cookie. |
| `SESSION_COOKIE_DOMAIN` | string | empty | Domain of the cookie: empty is the host that set it, without its subdomains. |
| `SESSION_COOKIE_SECURE` | bool | `true` | The cookie is sent only by HTTPS. In development over HTTP set it to `false`. |
| `SESSION_COOKIE_HTTP_ONLY` | bool | `true` | The cookie is not readable by JavaScript. |
| `SESSION_COOKIE_SAMESITE` | string | `Lax` | `SameSite` of the cookie: `Lax` keeps it from going in a POST from another site. |
| `SESSION_CACHE_LIMITER` | string | `nocache` | Cache limiter of PHP. |
| `SESSION_CACHE_EXPIRE_MINUTES` | int | `180` | Cache expire of PHP, in minutes. |

The defaults are declared as strings, which is what Symfony asks of the default of an environment variable.

## What a request does

The session of a visitor is created when something is written in it, and not before: a visitor that only reads pages that do not use the session does not get a cookie. A session that did not change does not set the cookie again.



---
Last updated on 08/10/2026

