Skip to main content

Module session

Module session 

Source
Expand description

Random tokens, their hashes, and the session cookie.

Spec section 8: sessions are random IDs in HttpOnly / Secure / SameSite=Lax cookies, stored hashed. The same 32-byte random token and SHA-256 hash serve magic links.

Constants§

SESSION_COOKIE
SESSION_TTL

Functions§

cookie
Reads one cookie from the request.
hash
What gets stored instead of the token itself.
random_token
32 random bytes as URL-safe base64 (43 characters).
set_cookie
A Set-Cookie value. max_age of zero clears the cookie.
start
Creates a session for the account and returns the Set-Cookie header value.