celema / session
Celema session library
Requires
- php: ^8.5
- ext-random: *
Requires (Dev)
- celema/dev: ^5.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
Helper classes for native PHP sessions, flash messages, and CSRF.
Installation
composer require celema/session
Documentation
Start here: docs/index.md.
Quick start
use Celema\Session\Session; $session = new Session(); $session->start(); $session->set('user_id', 123); $userId = $session->get('user_id'); $session->flash->add('Signed in.'); $token = $session->csrf->token('profile');
Session merges custom options with secure defaults for Secure and HttpOnly cookies, SameSite=Lax, strict session IDs, cookie-only session IDs, disabled transparent session IDs, and PHP's nocache session cache limiter. Set cookie_secure to false only for intentional plain HTTP environments, such as local development without TLS.
Mutation testing
Mutation testing with Infection is not part of composer ci, but the CI workflow runs it after the coverage step and enforces the minimum mutation score from infection.json5.dist. Pushes only mutate the changed lines; a weekly scheduled run covers the whole codebase. Run it locally with:
composer mutation
Reports are written to .infection/.
License
This project is licensed under the MIT license.