FrostMVC\Session
use FrostMVC\Session;
Encrypted, optionally Memcached-backed PHP session wrapper.
String and numeric values are transparently encrypted via Security::encrypt() before storage and decrypted on retrieval. Non-scalar values (arrays, objects) are stored without encryption.
Session key names are obfuscated with SHA1/MD5 hashing when encryption is enabled, masking the meaning of session fields from server-side inspection.
| Property | Type | Description |
|---|---|---|
| Session::$global | ?FrostMVC\FlashLog |
| ->__construct() | — |
| ::check() | Returns true when the decrypted value of the named key equals one of the provided values. Uses strict comparison. |
| ::close() | Writes the session data and releases the lock, allowing concurrent requests to proceed without blocking on this session's file lock. Reads continue to work from the in-memory snapshot until a write reopens the session. |
| ::destroy() | Destroys the active session, or the stored session data for the given raw session id without starting or creating a session. |
| ::flash() | Reads and immediately removes the value for the given key (read-once). |
| ::get() | Retrieves a value from the session. Decrypts scalar values via Security::decrypt(). Returns $defaultValue when the key is absent or decryption yields an empty string. |
| ::getKey() | Returns the stored hashed session key for the given name, or the root session ID key when no name is provided. |
| ::id() | Returns the active PHP session id, starting the session when needed. |
| ::memcached() | Configures the session to use a Memcached server as its backend. Falls back to standard PHP sessions when the server is unreachable or the Memcached extension is unavailable. |
| ::remove() | Removes the named key from the session. |
| ::set() | Stores a value in the session under the given key. String and numeric values are encrypted before storage. |
| ::setEncryptID() | Controls whether key names are hashed before storage. Hashing is enabled by default and recommended in production. |
| ::setKey() | Sets the root session identifier to the given value. |
| ::setOption() | Overrides a single session INI option during start(). |
| ::settings() | Replaces the entire session options array. Call before start() if you need to override multiple options at once. |
| ::start() | Starts the session if it has not already been started. |
$session->__construct()
No description yet.
Session::check($what, ...$value)
Returns true when the decrypted value of the named key equals one of the provided values. Uses strict comparison.
| $what | string |
The logical key. |
| ...$value | mixed |
One or more values to match against. |
bool
Session::close()
Writes the session data and releases the lock, allowing concurrent requests to proceed without blocking on this session's file lock. Reads continue to work from the in-memory snapshot until a write reopens the session.
Session::destroy($sessionID = false)
Destroys the active session, or the stored session data for the given raw session id without starting or creating a session.
| $sessionID | string|false |
The raw PHP session id to destroy, or false for the active session. Default:false |
bool
Session::flash($name, $defaultValue = false)
Reads and immediately removes the value for the given key (read-once).
| $name | string |
The logical key. |
| $defaultValue | mixed |
Returned when the key is absent. Default:false |
mixed
Session::get($name, $defaultValue = false)
Retrieves a value from the session. Decrypts scalar values via Security::decrypt(). Returns $defaultValue when the key is absent or decryption yields an empty string.
| $name | string |
The logical key. |
| $defaultValue | mixed |
Returned when the key is absent. Default:false |
mixed
Session::getKey($name = false)
Returns the stored hashed session key for the given name, or the root session ID key when no name is provided.
| $name | string|false |
Logical key name, or false for the root key. Default:false |
string|false
Session::id()
Returns the active PHP session id, starting the session when needed.
string
Session::memcached($ip, $port = 11211)
Configures the session to use a Memcached server as its backend. Falls back to standard PHP sessions when the server is unreachable or the Memcached extension is unavailable.
| $ip | string |
The Memcached server IP address. |
| $port | int |
The Memcached port. Defaults to 11211. Default:11211 |
Memcached|false The handler instance, or false on failure.
Session::remove($name)
Removes the named key from the session.
| $name | string |
The logical key. |
bool Always true.
Session::set($name, $value)
Stores a value in the session under the given key. String and numeric values are encrypted before storage.
| $name | string |
The logical key. |
| $value | mixed |
The value to store. |
Session::setEncryptID($encrypt = true)
Controls whether key names are hashed before storage. Hashing is enabled by default and recommended in production.
| $encrypt | bool |
Default: true |
Session::setKey($value)
Sets the root session identifier to the given value.
| $value | mixed |
Session::setOption($option, $value)
Overrides a single session INI option during start().
| $option | string |
A session.* INI key without the 'session.' prefix. |
| $value | mixed |
The value for the option. |
Session::settings($settings)
Replaces the entire session options array. Call before start() if you need to override multiple options at once.
| $settings | array |
Associative array of session.* options. |
Session::start()
Starts the session if it has not already been started.
bool True on success.
Generated from core/classes/Session.php (FrostMVC ).