1 package Catalyst::Plugin::Session::State::Cookie;
2 use base qw/Catalyst::Plugin::Session::State/;
8 use Catalyst::Utils ();
10 our $VERSION = "0.05";
15 $c->NEXT::setup_session(@_);
17 $c->config->{session}{cookie_name}
18 ||= Catalyst::Utils::appprefix($c) . '_session';
21 sub extend_session_id {
22 my ( $c, $sid, $expires ) = @_;
24 if ( my $cookie = $c->get_session_cookie ) {
25 $c->update_session_cookie( $c->make_session_cookie( $sid ) );
28 $c->NEXT::extend_session_id( $sid, $expires );
34 $c->update_session_cookie( $c->make_session_cookie( $sid ) );
36 return $c->NEXT::set_session_id($sid);
39 sub update_session_cookie {
40 my ( $c, $updated ) = @_;
42 unless ( $c->cookie_is_rejecting( $updated ) ) {
43 my $cookie_name = $c->config->{session}{cookie_name};
44 $c->response->cookies->{$cookie_name} = $updated;
48 sub cookie_is_rejecting {
49 my ( $c, $cookie ) = @_;
51 if ( $cookie->{path} ) {
52 return 1 if index '/'.$c->request->path, $cookie->{path};
58 sub make_session_cookie {
59 my ( $c, $sid, %attrs ) = @_;
61 my $cfg = $c->config->{session};
64 ( $cfg->{cookie_domain} ? ( domain => $cfg->{cookie_domain} ) : () ),
65 ( $cfg->{cookie_path} ? ( path => $cfg->{cookie_path} ) : () ),
69 unless ( exists $cookie->{expires} ) {
70 $cookie->{expires} = $c->calculate_session_cookie_expires();
73 $cookie->{secure} = 1 if $cfg->{cookie_secure};
78 sub calc_expiry { # compat
80 $c->NEXT::calc_expiry( @_ ) || $c->calculate_session_cookie_expires( @_ );
83 sub calculate_session_cookie_expires {
85 my $cfg = $c->config->{session};
87 my $value = $c->NEXT::calculate_session_cookie_expires(@_);
88 return $value if $value;
90 if ( exists $cfg->{cookie_expires} ) {
91 if ( $cfg->{cookie_expires} > 0 ) {
92 return time() + $cfg->{cookie_expires};
99 return $c->session_expires;
103 sub get_session_cookie {
106 my $cookie_name = $c->config->{session}{cookie_name};
108 return $c->request->cookies->{$cookie_name};
114 if ( my $cookie = $c->get_session_cookie ) {
115 my $sid = $cookie->value;
116 $c->log->debug(qq/Found sessionid "$sid" in cookie/) if $c->debug;
120 $c->NEXT::get_session_id(@_);
123 sub delete_session_id {
124 my ( $c, $sid ) = @_;
126 $c->update_session_cookie( $c->make_session_cookie( $sid, expires => 0 ) );
128 $c->NEXT::delete_session_id($sid);
139 Catalyst::Plugin::Session::State::Cookie - Maintain session IDs using cookies.
143 use Catalyst qw/Session Session::State::Cookie Session::Store::Foo/;
147 In order for L<Catalyst::Plugin::Session> to work the session ID needs to be
148 stored on the client, and the session data needs to be stored on the server.
150 This plugin stores the session ID on the client using the cookie mechanism.
156 =item make_session_cookie
158 Returns a hash reference with the default values for new cookies.
160 =item update_session_cookie $hash_ref
162 Sets the cookie based on C<cookie_name> in the response object.
166 =head1 EXTENDED METHODS
170 =item prepare_cookies
172 Will restore if an appropriate cookie is found.
174 =item finalize_cookies
176 Will set a cookie called C<session> if it doesn't exist or if it's value is not
177 the current session id.
181 Will set the C<cookie_name> parameter to it's default value if it isn't set.
191 The name of the cookie to store (defaults to C<Catalyst::Utils::apprefix($c) . '_session'>).
195 The name of the domain to store in the cookie (defaults to current host)
199 Number of seconds from now you want to elapse before cookie will expire.
200 Set to 0 to create a session cookie, ie one which will die when the
201 user's browser is shut down.
205 If this attribute set true, the cookie will only be sent via HTTPS.
209 The path of the request url where cookie should be baked.
215 Sessions have to be created before the first write to be saved. For example:
218 my ( $self, $c ) = @_;
219 $c->res->write("foo");
224 Will cause a session ID to not be set, because by the time a session is
225 actually created the headers have already been sent to the client.
229 L<Catalyst>, L<Catalyst::Plugin::Session>.
233 This module is derived from L<Catalyst::Plugin::Session::FastMmap> code, and
234 has been heavily modified since.
239 Yuval Kogman, C<nothingmuch@woobling.org>
245 This program is free software, you can redistribute it and/or modify it
246 under the same terms as Perl itself.