Updated Changes
[catagits/Catalyst-Plugin-Session.git] / Changes
CommitLineData
a552e4b5 1Revision history for Perl extension Catalyst::Plugin::Session
2
7b420171 3 - Fixed a bug when "expiry_threshold" is non-zero, where changes to the
4 session were not saved.
5
9cfd00b3 60.38 2013-09-18
7 - New feature: "expiry_threshold" which allows you more control over when
8 this plugin checks and updates the expiration date for the session.
9 This is useful when you have high traffic and need to reduce the number
10 of session expiration hits (like if you are using a database for sessions
11 and your db is getting pounded).
12
06d0ceb7 130.37 2013-02-25
d681594f 14 - Fix t/live_verify_address.t to skip if Catalyst::Plugin::Authentication
d7cb2327 15 is not installed, fixing RT#81506.
16
e7e91d88 170.36 2012-10-19
18 - Re-pack with new Module::Install which doesn't get
19 MYMETA.yaml wrong.
20 - Remove use of Plack::Middleware::ForceEnv from the tests
df76da4a 21 as it was not used / needed
22
a3dc40ab 230.35 2012-04-24
221e3f29 24 - Implement a 'change_session_expires' method (gshank)
25
26 - Fixed bug from last version where session does not persist
27 across a redirect
a2e23c04 28
f2993f24 290.34 2012-03-30
30 - Fixed up t/live_verify_address.t per https://rt.cpan.org/Ticket/Display.html?id=71142
76b677b4 31 - Merged in dpetrov's 0.32 changes (extend_session_expire)
f2993f24 32
ad3142b4 330.33 2012-03-08
34 - Note that flash is deprecated / not recommended due to it's
35 inherent races. Point out Catalyst::Plugin::StatusMessage instead
36
b212d3b2 370.32 2011-06-08
38 - Fix handling with enables verify_address and add related test
39
f4f73302 400.31 2010-10-08
834ab0b8 41 - Fix session being loaded by call to dump_these in debug mode
42 (RT#58856)
43
5d56ebde 440.30 2010-06-24
c0430ac1 45 - Fix Makefile.PL's is_upgrading_needed() routine (RT #58771)
46
382d6092 470.29 2009-11-04
e8ce5753 48 - Fix session being deleted when you have a new session after session
49 expiry when calling session_is_valid method. Tests for this.
bb5f369a 50 - Allow ->session to be used as a setter method so that you can say
51 ->session( key => $value );
52
836b0a11 530.28 2009-10-29
54 - Fix session fixation test with LWP 5.833 by calling $cookie_jar->set_cookie
55 rather than manually stuffing the cookie in the request.
56
1c4a1a43 570.27 2009-10-08
58 - Release 0.26_01 as stable without further changes.
59
9a50355f 600.26_01 2009-10-06
064c3709 61 - Move actions out of the root application class in tests as this
62 is deprecated.
63 - Change configuration key to 'Plugin::Session' by default. The
64 old 'session' key is still supported, but will issue a warning
65 in a future release.
66
a4bd5693 670.26 2009-08-19
6945eb54 68 - Remove Test::MockObject from the test suite as prone to failing on
69 some platforms and perl versions due to it's UNIVERSAL:: package
70 dependencies.
a4bd5693 71
720.25 2009-07-08
af1e4bc8 73 - Add the a change_session_id method which can be called after
74 authentication to change the user's session cookie whilst preserving
75 their session data. This can be used to provide protection from
76 Session Fixation attacks. (kmx)
77
f8f81744 780.24 2009-06-23
79 - Be more paranoid about getting values of $c->req to avoid issues
80 with old Test::WWW::Mechanize::Catalyst.
81 - Check we have a modern version of TWMC before doing the tests which
82 need it.
83
e79a686c 840.23 2009-06-16
b97042c0 85 - Add the verify_user_agent config parameter (kmx)
1c4a1a43 86 - Add a test case to prove that logging in with a session cookie still
b97042c0 87 causes a new cookie to be issued for you, proving that the code is
88 not vulnerable to a session fixation attack. (t0m)
73d1f3a2 89
3253438d 900.22 2009-05-13
91 - INSANE HACK to ensure B::Hooks::EndOfScope inlines us a new method right now
1c4a1a43 92 in Catalyst::Plugin::Session::Test::Store for Catalyst 5.80004 compatibility.
3253438d 93
94 This change does not in any way affect normal users - it is just due to the
95 fairly crazy way that Catalyst::Plugin::Session::Test::Store works, and that
96 module is _only_ used for unit testing session store plugins pre-installation.
97
98 Session::Test::Store should be replaced with a more sane solution, and other
99 CPAN modules using it moved away from using it, but this change keeps stops
100 new Catalyst breaking other distributions right now.
101
eee1173f 1020.21 2009-04-30
66017cbc 103 - Hide the internal packages in Catalyst::Plugin::Session::Test::Store from PAUSE.
fff59d60 104 - Convert from CAF to Moose with Moosex::Emulate::Class::Accessor::Fast
66017cbc 105
87ed5295 1060.20 2009-02-05
107 - No code changes since 0.19_01 dev release.
108 - Add IDEAS.txt which is an irc log of discussion about the next-generation
109 session plugin from discussion on #catalyst-dev
110 - Remove TODO file, which is no longer relevant.
111
2842d938 1120.19_01 2009-01-09
7550f095 113 - Switch from using NEXT to Class::C3 for method re-dispatch.
114 - Use shipit to package the dist.
115 - Switch to Module::install.
eb250519 116 - Flash data is now stored inside the session (key "__flash") to avoid
117 duplicate entry errors caused by simultaneous select/insert/delete of
2842d938 118 flash rows when using DBI as a Store. (Sergio Salvi)
119 - Fix session finalization order that caused HTTP responses to be sent
120 before the session is actually finalized and stored in its Store.
121 (Sergio Salvi)
7048c24e 122
1230.19 2007-10-08
124
e3496e48 1250.18 2007-08-15
126 - Fix Apache engine issue (RT #28845)
c4dc7ba9 127
e3496e48 1280.17 2007-07-16
129 - Skip a test if Cookie is not installed (RT #28137)
c48f1a4e 130
e3496e48 1310.16 2007-07-03
bcdad401 132 - Stupid makefile
133
e3496e48 1340.15 2007-06-24
38761943 135 - Fix the bug that caused sessions to expire immediately when another
136 session was deleted previously in the same request cycle
84f65b2e 137 - Changed finalize() to redispatch before saving session
138 so other finalize methods still have access to it.
38761943 139
e3496e48 1400.14 2007-01-31
86553855 141 - Disable verify_address.
142 - update flash to work like session
143
e3496e48 1440.13 2006-10-12
177c24fe 145 - Rerelease with slightly changed test due to a behavior change in
146 Test::MockObject
5a1f6ed4 147 - add `clear_flash`
49727697 148 - improve debug logging
149
e3496e48 1500.12 2006-08-26
8f236527 151 - refactor out a hookable finalize_session method, for plugins
152 - make _clear_session_instance_data call NEXT::, so that plugins can
153 hook on to that too
154
e3496e48 1550.11 2006-08-10
260b14c4 156 - Lazify expiry calculation and store it in a different instance data
157 slot. This provides greater flexibility for implementing hooks like
158 DynamicExpiry the "right" way.
159
e3496e48 1600.10 2006-08-01
23a2bf16 161 - Implement a more well defined finalization order for Session stuff.
162 This solves a problem that was introduced by some value cleanups in
163 the 0.06 release.
164
e3496e48 1650.09 2006-07-31
ec299c02 166 - Fix Catalyst::Plugin::Session::Test::Store
167
e3496e48 1680.08 2006-07-31
ec270ef0 169 - rerelease because Module::Bane broke the META.yml. HURAAH
170
e3496e48 1710.07 2006-07-30
340449a2 172 - Make build tool complain loudly on incompatible versions of state
173 plugins.
174
e3496e48 1750.06 2006-07-29
6f327a6c 176 - Change State plugin API to be pull oriented
177 - Lazify more correctly (mostly performance improvements)
178 - Don't try to compute digest of hash when there is no hash
bab8b74b 179
e3496e48 1800.05 2006-01-01
7db1c46a 181 - Un-workaround the Cache::FastMmap (actually Storable) limitation -
182 it's not C::P::Session's business.
183 - add $c->session_expires
184 - refactor guts
185 - improve semantics of session deletion (now deletes flash data too)
186 - improve lazy-load-ness of session data in the light of expiration
187
7a02371f 1880.04 2005-12-28 09:42:00
189 - Work around a limitation in Cache::FastMmap - must store only
190 references, while expiration was an NV.
191
1920.03 2005-12-26 10:22:00
a552e4b5 193 - Lazify loading of session data for better performance and less chance
194 of race conditions
9b0fa2a6 195 - support for $c->flash a la Ruby on Rails
5faaa4b0 196 - Fixed bug in sessionid algorithm detection.
4207ce8d 197 - Separate __expires from the session data - we write it every time
198 - Lazify saving of session data for better performance and less chance
199 of race conditions
a552e4b5 200
5faaa4b0 2010.02 2005-11-23 09:40:00
a552e4b5 202 - Doc fixes
203 - No more -Engine=Test
204
5faaa4b0 2050.01 2005-11-14 12:41:00
a552e4b5 206 - Initial release.