Expand description
Random tokens, their hashes, and the session cookie.
Spec section 8: sessions are random IDs in HttpOnly / Secure / SameSite=Lax cookies, stored hashed. The same 32-byte random token and SHA-256 hash serve magic links.
Constants§
Functions§
- cookie
- Reads one cookie from the request.
- hash
- What gets stored instead of the token itself.
- random_
token - 32 random bytes as URL-safe base64 (43 characters).
- set_
cookie - A
Set-Cookievalue.max_ageof zero clears the cookie. - start
- Creates a session for the account and returns the
Set-Cookieheader value.