trail / sessions
Database sessions for trail
dev-main / 0.1.x-dev
2026-10-01 03:26 UTC
Requires
- php: >=8.4
- trail/db: ^0.1
- trail/framework: ^0.1
Requires (Dev)
None
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-10-01 03:26:14 UTC
README
Session handling for trail framework
install
composer require trail/sessions
trail/trail db::migrate
Requires trail/db. Every request now has a Session in the box.
use it
Ask for it in handle(). Stuff is stored as json so keep that in mind.
use Trail\Sessions\Session\Session;
public function handle(Session $session): Response
{
$session->put('theme', 'dark');
$session->get('theme', 'light');
$session->has('theme');
$session->pull('once'); // get + forget
$session->forget('theme');
$session->flash('notice', 'saved'); // next request
...
}
how it works
- nothing touches the database until something gets added
- cookie has a random token. table holds its sha256
- sessions that go empty delete their row + cookie
- busy sessions caress their row once a minute at most
- guest never comes back dies after an hour (bots, curl, whatever)
- registers with freeze addon so anyone with a session can skip cache
For auth addons (or whatever)
$session->claim($userId); // set user + swap token
$session->renew(); // swap token + keep stuff
$session->destroy(); // wipe everything
$session->userId();
Locker lists and kills sessions per user. For "your devices" pages
$locker->forUser($userId);
$locker->evict($userId, $id);
$locker->evictAll($userId, except: $session->id);
config
In app.php
'sessions' => [
// idle seconds before it dies. 2 weeks
'lifetime' => 1209600,
// https only cookie
'secure' => true,
// __Host-trail_session by default. trail_session when not secure
'cookie' => null,
],
cli
Expired table rows hang around until you prune them. Cleanup with a command
trail/trail sessions::prune