Welcome to FrostSW!

FrostMVC PHP Framework

Documentation   |   Version

Session

FrostMVC\Session

use FrostMVC\Session;

Encrypted, optionally Memcached-backed PHP session wrapper.

String and numeric values are transparently encrypted via Security::encrypt() before storage and decrypted on retrieval. Non-scalar values (arrays, objects) are stored without encryption.

Session key names are obfuscated with SHA1/MD5 hashing when encryption is enabled, masking the meaning of session fields from server-side inspection.

Properties

PropertyTypeDescription
Session::$global ?FrostMVC\FlashLog

Methods

->__construct() —
::check()

Returns true when the decrypted value of the named key equals one of the provided values. Uses strict comparison.

::close()

Writes the session data and releases the lock, allowing concurrent requests to proceed without blocking on this session's file lock. Reads continue to work from the in-memory snapshot until a write reopens the session.

::destroy()

Destroys the active session, or the stored session data for the given raw session id without starting or creating a session.

::flash()

Reads and immediately removes the value for the given key (read-once).

::get()

Retrieves a value from the session. Decrypts scalar values via Security::decrypt(). Returns $defaultValue when the key is absent or decryption yields an empty string.

::getKey()

Returns the stored hashed session key for the given name, or the root session ID key when no name is provided.

::id()

Returns the active PHP session id, starting the session when needed.

::memcached()

Configures the session to use a Memcached server as its backend. Falls back to standard PHP sessions when the server is unreachable or the Memcached extension is unavailable.

::remove()

Removes the named key from the session.

::set()

Stores a value in the session under the given key. String and numeric values are encrypted before storage.

::setEncryptID()

Controls whether key names are hashed before storage. Hashing is enabled by default and recommended in production.

::setKey()

Sets the root session identifier to the given value.

::setOption()

Overrides a single session INI option during start().

::settings()

Replaces the entire session options array. Call before start() if you need to override multiple options at once.

::start()

Starts the session if it has not already been started.

__construct()

$session->__construct()

No description yet.

check() static

Session::check($what, ...$value)

Returns true when the decrypted value of the named key equals one of the provided values. Uses strict comparison.

Parameters

$what string

The logical key.

...$value mixed

One or more values to match against.

Returns

bool

close() static

Session::close()

Writes the session data and releases the lock, allowing concurrent requests to proceed without blocking on this session's file lock. Reads continue to work from the in-memory snapshot until a write reopens the session.

destroy() static

Session::destroy($sessionID = false)

Destroys the active session, or the stored session data for the given raw session id without starting or creating a session.

Parameters

$sessionID string|false

The raw PHP session id to destroy, or false for the active session.

Default: false

Returns

bool

flash() static

Session::flash($name, $defaultValue = false)

Reads and immediately removes the value for the given key (read-once).

Parameters

$name string

The logical key.

$defaultValue mixed

Returned when the key is absent.

Default: false

Returns

mixed

get() static

Session::get($name, $defaultValue = false)

Retrieves a value from the session. Decrypts scalar values via Security::decrypt(). Returns $defaultValue when the key is absent or decryption yields an empty string.

Parameters

$name string

The logical key.

$defaultValue mixed

Returned when the key is absent.

Default: false

Returns

mixed

getKey() static

Session::getKey($name = false)

Returns the stored hashed session key for the given name, or the root session ID key when no name is provided.

Parameters

$name string|false

Logical key name, or false for the root key.

Default: false

Returns

string|false

id() static

Session::id()

Returns the active PHP session id, starting the session when needed.

Returns

string

memcached() static

Session::memcached($ip, $port = 11211)

Configures the session to use a Memcached server as its backend. Falls back to standard PHP sessions when the server is unreachable or the Memcached extension is unavailable.

Parameters

$ip string

The Memcached server IP address.

$port int

The Memcached port. Defaults to 11211.

Default: 11211

Returns

Memcached|false The handler instance, or false on failure.

remove() static

Session::remove($name)

Removes the named key from the session.

Parameters

$name string

The logical key.

Returns

bool Always true.

set() static

Session::set($name, $value)

Stores a value in the session under the given key. String and numeric values are encrypted before storage.

Parameters

$name string

The logical key.

$value mixed

The value to store.

setEncryptID() static

Session::setEncryptID($encrypt = true)

Controls whether key names are hashed before storage. Hashing is enabled by default and recommended in production.

Parameters

$encrypt bool Default: true

setKey() static

Session::setKey($value)

Sets the root session identifier to the given value.

Parameters

$value mixed

setOption() static

Session::setOption($option, $value)

Overrides a single session INI option during start().

Parameters

$option string

A session.* INI key without the 'session.' prefix.

$value mixed

The value for the option.

settings() static

Session::settings($settings)

Replaces the entire session options array. Call before start() if you need to override multiple options at once.

Parameters

$settings array

Associative array of session.* options.

start() static

Session::start()

Starts the session if it has not already been started.

Returns

bool True on success.

Generated from core/classes/Session.php (FrostMVC ).