package Catalyst::Plugin::Session::State::Cookie;
-use base qw/Catalyst::Plugin::Session::State/;
+use base qw/Catalyst::Plugin::Session::State Class::Accessor::Fast/;
use strict;
use warnings;
-use NEXT;
+use MRO::Compat;
use Catalyst::Utils ();
-our $VERSION = "0.02";
+our $VERSION = "0.11";
+
+BEGIN { __PACKAGE__->mk_accessors(qw/_deleted_session_id/) }
sub setup_session {
my $c = shift;
- $c->NEXT::setup_session(@_);
+ $c->maybe::next::method(@_);
$c->config->{session}{cookie_name}
||= Catalyst::Utils::appprefix($c) . '_session';
$c->update_session_cookie( $c->make_session_cookie( $sid ) );
}
- $c->NEXT::extend_session_id( @_ );
+ $c->maybe::next::method( $sid, $expires );
}
sub set_session_id {
$c->update_session_cookie( $c->make_session_cookie( $sid ) );
- return $c->NEXT::set_session_id(@_);
+ return $c->maybe::next::method($sid);
}
sub update_session_cookie {
my ( $c, $updated ) = @_;
- my $cookie_name = $c->config->{session}{cookie_name};
- $c->response->cookies->{$cookie_name} = $updated;
+
+ unless ( $c->cookie_is_rejecting( $updated ) ) {
+ my $cookie_name = $c->config->{session}{cookie_name};
+ $c->response->cookies->{$cookie_name} = $updated;
+ }
+}
+
+sub cookie_is_rejecting {
+ my ( $c, $cookie ) = @_;
+
+ if ( $cookie->{path} ) {
+ return 1 if index '/'.$c->request->path, $cookie->{path};
+ }
+
+ return 0;
}
sub make_session_cookie {
my $cfg = $c->config->{session};
my $cookie = {
value => $sid,
- %attrs,
( $cfg->{cookie_domain} ? ( domain => $cfg->{cookie_domain} ) : () ),
+ ( $cfg->{cookie_path} ? ( path => $cfg->{cookie_path} ) : () ),
+ %attrs,
};
unless ( exists $cookie->{expires} ) {
sub calc_expiry { # compat
my $c = shift;
- $c->NEXT::calc_expiry( @_ ) || $c->calculate_session_cookie_expires( @_ );
+ $c->maybe::next::method( @_ ) || $c->calculate_session_cookie_expires( @_ );
}
sub calculate_session_cookie_expires {
my $c = shift;
my $cfg = $c->config->{session};
- my $value = $c->NEXT::calculate_session_cookie_expires(@_);
+ my $value = $c->maybe::next::method(@_);
return $value if $value;
if ( exists $cfg->{cookie_expires} ) {
sub get_session_id {
my $c = shift;
- if ( my $cookie = $c->get_session_cookie ) {
+ if ( !$c->_deleted_session_id and my $cookie = $c->get_session_cookie ) {
my $sid = $cookie->value;
$c->log->debug(qq/Found sessionid "$sid" in cookie/) if $c->debug;
return $sid if $sid;
}
- $c->NEXT::get_session_id(@_);
+ $c->maybe::next::method(@_);
}
sub delete_session_id {
- my $c = shift;
- $c->NEXT::delete_session_id();
- delete $c->response->cookies->{ $c->config->{session}{cookie_name} };
+ my ( $c, $sid ) = @_;
+
+ $c->_deleted_session_id(1); # to prevent get_session_id from returning it
+
+ $c->update_session_cookie( $c->make_session_cookie( $sid, expires => 0 ) );
+
+ $c->maybe::next::method($sid);
}
__PACKAGE__
Sets the cookie based on C<cookie_name> in the response object.
+=item calc_expiry
+
+=item calculate_session_cookie_expires
+
+=item cookie_is_rejecting
+
+=item delete_session_id
+
+=item extend_session_id
+
+=item get_session_cookie
+
+=item get_session_id
+
+=item set_session_id
+
=back
=head1 EXTENDED METHODS
=item finalize_cookies
-Will set a cookie called C<session> if it doesn't exist or if it's value is not
+Will set a cookie called C<session> if it doesn't exist or if its value is not
the current session id.
=item setup_session
-Will set the C<cookie_name> parameter to it's default value if it isn't set.
+Will set the C<cookie_name> parameter to its default value if it isn't set.
=back
If this attribute set true, the cookie will only be sent via HTTPS.
+=item cookie_path
+
+The path of the request url where cookie should be baked.
+
=back
+For example, you could stick this in MyApp.pm:
+
+ __PACKAGE__->config( session => {
+ cookie_domain => '.mydomain.com',
+ });
+
=head1 CAVEATS
Sessions have to be created before the first write to be saved. For example:
=head1 AUTHORS
+Yuval Kogman E<lt>nothingmuch@woobling.orgE<gt>
+
+=head1 CONTRIBUTORS
+
This module is derived from L<Catalyst::Plugin::Session::FastMmap> code, and
has been heavily modified since.
-Andrew Ford
-Andy Grundman
-Christian Hansen
-Yuval Kogman, C<nothingmuch@woobling.org>
-Marcus Ramberg
-Sebastian Riedel
+ Andrew Ford
+ Andy Grundman
+ Christian Hansen
+ Marcus Ramberg
+ Jonathan Rockway E<lt>jrockway@cpan.orgE<gt>
+ Sebastian Riedel
=head1 COPYRIGHT