GSP
Quick Navigator

Search Site

Unix VPS
A - Starter
B - Basic
C - Preferred
D - Commercial
MPS - Dedicated
Previous VPSs
* Sign Up! *

Support
Contact Us
Online Help
Handbooks
Domain Status
Man Pages

FAQ
Virtual Servers
Pricing
Billing
Technical

Network
Facilities
Connectivity
Topology Map

Miscellaneous
Server Agreement
Year 2038
Credits
 

USA Flag

 

 

Man Pages


Manual Reference Pages  -  PLACK::SESSION::STATE (3)

.ds Aq ’

NAME

Plack::Session::State - Basic parameter-based session state

CONTENTS

SYNOPSIS



  use Plack::Builder;
  use Plack::Middleware::Session;
  use Plack::Session::State;

  my $app = sub {
      return [ 200, [ Content-Type => text/plain ], [ Hello Foo ] ];
  };

  builder {
      enable Session,
          state => Plack::Session::State->new;
      $app;
  };



DESCRIPTION

This will maintain session state by passing the session through the request params. It does not do this automatically though, you are responsible for passing the session param.

This should be considered the state base class (although subclassing is not a requirement) and defines the spec for all <B>Plack::Session::State::*B> modules. You will only need to override a couple methods if you do subclass. See Plack::Session::State::Cookie for an example of this.

<B>WARNINGB>: parameter based session ID management makes session fixation really easy, and that makes your website vulnerable. You should really avoid using this state in the production environment except when you have to deal with legacy HTTP clients that do not support cookies.

In the future this parameter based state handling will be removed from this base class and will be moved to its own State class.

METHODS

<B>new ( B>%params<B> )B> The %params can include session_key, sid_generator and sid_checker however in both cases a default will be provided for you.
<B>session_keyB> This is the name of the session key, it defaults to ’plack_session’.
<B>sid_generatorB> This is a CODE ref used to generate unique session ids, by default it will generate a SHA1 using fairly sufficient entropy. If you are concerned or interested, just read the source.
<B>sid_validatorB> This is a regex used to validate requested session id.

    Session ID Managment

<B>get_session_id ( B>$env<B> )B> This is the method used to extract the session id from a $env. Subclasses will often only need to override this method and the finalize method.
<B>validate_session_id ( B>$session_id<B> )B> This will use the sid_validator regex and confirm that the $session_id is valid.
<B>extract ( B>$env<B> )B> This will attempt to extract the session from a $env by looking for the session_key in the request params. It will then check to see if the session is valid and that it has not expired. It will return the session id if everything is good or undef otherwise.
<B>generate ( B>$request<B> )B> This will generate a new session id using the sid_generator callback. The $request argument is not used by this method but is there for use by subclasses. The $request is expected to be a Plack::Request instance or an object with an equivalent interface.
<B>finalize ( B>$session_id<B>, B>$response<B> )B> Given a $session_id and a $response this will perform any finalization necessary to preserve state. This method is called by the Plack::Session finalize method. The $response is expected to be a Plack::Response instance or an object with an equivalent interface.

    Session Expiration Handling

<B>expire_session_id ( B>$id<B>, B>$response<B> )B> This will mark the session for $id as expired. This method is called by the Plack::Session expire method.

BUGS

All complex software has bugs lurking in it, and this module is no exception. If you find a bug please either email me, or add the bug to cpan-RT.

AUTHOR

Stevan Little <stevan.little@iinteractive.com>

COPYRIGHT AND LICENSE

Copyright 2009, 2010 Infinity Interactive, Inc.

<http://www.iinteractive.com>

This library is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

Search for    or go to Top of page |  Section 3 |  Main Index


perl v5.20.3 PLACK::SESSION::STATE (3) 2015-03-02

Powered by GSP Visit the GSP FreeBSD Man Page Interface.
Output converted with manServer 1.07.