phpgt/session

Encapsulated user sessions.

Maintainers

Package info

github.com/PhpGt/Session

Issues

pkg:composer/phpgt/session

Fund package maintenance!

PhpGt

Statistics

Installs: 7 313

Dependents: 4

Suggesters: 0

Stars: 1


README

This library is a simple object oriented alternative to the $_SESSION superglobal allowing application code to be passed encapsulated SessionStore objects, so areas of code can have access to their own Session area without having full read-write access to all session variables.

Sessions are addressed using dot notation, allowing for handling categories of session data. This is particularly useful when dealing with user authentication, for example.

Build status Code quality Code coverage Current version PHP.Gt/Session documentation

Example usage: Welcome a user by their first name or log out the user

if($session->contains("auth")) {
// Remove the *whole* auth section of the session on logout.
	if($action === "logout") {
		$session->delete("auth");
	}
	else {
// Output a variable within the auth namespace:
		$message = "Welcome back, " . $session->getString("auth.user.name");
	}
}
else {
// Pass the "auth" store to a class, so it 
// can't read/write to other session variables:
	AuthenticationSystem::beginLogin($session->getStore("auth"));
}

Redis session storage

This package now includes Gt\Session\RedisHandler for shared session storage. It works with Redis-compatible backends such as Redis and Valkey, and is intended for deployments where application nodes are disposable and session state needs to survive traffic moving between servers.

RedisHandler expects save_path to be a DSN rather than a filesystem path. It uses the phpredis extension at runtime.

Example production config:

[session]
handler=Gt\Session\RedisHandler
save_path=rediss://default:secret@example-redis.internal:25061/0?prefix=GT:&ttl=1440
name=GT
use_cookies=true

Supported DSN forms:

  • redis://host:6379
  • redis://:password@host:6379/0
  • redis://username:password@host:6379/0
  • rediss://username:password@host:6379/0

Useful query parameters:

  • prefix: key prefix for stored sessions, defaults to <session-name>:
  • ttl: session lifetime in seconds, defaults to session.gc_maxlifetime
  • timeout: connection timeout in seconds
  • read_timeout: socket read timeout in seconds
  • persistent=1: enable persistent connections
  • persistent_id: optional persistent connection pool id
  • verify_peer=0 / verify_peer_name=0: optional TLS verification flags

Proudly sponsored by

JetBrains Open Source sponsorship program

JetBrains logo.