componenta / auth-session-http
PSR-7/PSR-15 browser transport for Componenta authentication sessions
Requires
- php: ^8.4
- componenta/auth: ^3.0
- componenta/auth-http: ^1.0
- componenta/auth-session: ^1.0
- componenta/http-csrf-middleware: ^2.0
- componenta/identity: ^1.0.1
- psr/clock: ^1.0
- psr/http-factory: ^1.0
- psr/http-message: ^2.0
- psr/http-server-handler: ^1.0
- psr/http-server-middleware: ^1.0
Requires (Dev)
- nyholm/psr7: ^1.8
- phpstan/phpstan: ^2.1
- phpunit/phpunit: ^12.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-27 22:46:40 UTC
README
Secure browser transport and PSR-15 integration for componenta/auth-session.
Active authentication sessions use a non-persistent __Host- cookie with
Secure, HttpOnly, Path=/ and explicit SameSite. Persistent
remember-me credentials belong to the future componenta/auth-remember-me
capability package.
This package also owns browser-only session security:
- pre-authentication cookie + request-token binding;
- session assurance middleware;
- activity tracking;
- authentication-session logout/publication;
- CSRF tokens bound to
AuthSession::$uuid + credentialGeneration.
CSRF lives under Componenta\Auth\Session\Http\Csrf; there is no separate
componenta/auth-session-csrf package in the Auth 3 architecture.
Session activity
Idle lifetime is fail-safe. AuthSessionActivityMiddleware touches a session
only when the request attribute SessionActivity::class equals
SessionActivity::Interactive. Unclassified/background requests and 401/403
responses do not extend idle expiry.