$c->config->{session}{cookie_name} ||= "session";
}
-sub finalize {
+sub finalize_cookies {
my $c = shift;
+ if ( $c->sessionid) {
+ $c->update_session_cookie( $c->make_session_cookie );
+ }
+
+ return $c->NEXT::finalize_cookies(@_);
+}
+
+sub update_session_cookie {
+ my ( $c, $updated ) = @_;
my $cookie_name = $c->config->{session}{cookie_name};
+ $c->response->cookies->{$cookie_name} = $updated;
+}
- if ( my $sid = $c->sessionid ) {
- my $cookie = $c->request->cookies->{$cookie_name};
- if ( !$cookie or $cookie->value ne $sid ) {
- $c->response->cookies->{$cookie_name} = {
- value => $sid,
- expires => $c->session->{__expires},
- };
- $c->log->debug(qq/A cookie with the session id "$sid" was saved/)
- if $c->debug;
- }
- }
+sub make_session_cookie {
+ my $c = shift;
+
+ my $cfg = $c->config->{session};
+ my $cookie = {
+ value => $c->sessionid,
+ ($cfg->{cookie_domain} ? (domain => $cfg->{cookie_domain}) : ()),
+ };
+
+ if ( exists $cfg->{cookie_expires} ) {
+ if ( my $ttl = $cfg->{cookie_expires} ) {
+ $cookie->{expires} = time() + $ttl;
+ } # else { cookie is non-persistent }
+ } else {
+ $cookie->{expires} = $c->session->{__expires};
+ }
- return $c->NEXT::finalize(@_);
+ return $cookie;
}
sub prepare_cookies {
Will restore if an appropriate cookie is found.
-=item finalize
+=item finalize_cookies
Will set a cookie called C<session> if it doesn't exist or if it's value is not
the current session id.
The name of the cookie to store (defaults to C<session>).
+=item cookie_domain
+
+The name of the domain to store in the cookie (defaults to current host)
+
=back
+=item CAVEATS
+
+Sessions have to be created before the first write to be saved. For example:
+
+ sub action : Local {
+ my ( $self, $c ) = @_;
+ $c->res->write("foo");
+ $c->session( ... );
+ ...
+ }
+
+Will cause a session ID to not be set, because by the time a session is
+actually created the headers have already been sent to the client.
+
=head1 SEE ALSO
L<Catalyst>, L<Catalyst::Plugin::Session>.