Changes for version 0.23 - 2009-06-16

  • Add the verify_user_agent config parameter (kmx)
  • Add a test case to prove that logging in with a session cookie still causes a new cookie to be issued for you, proving that the code is not vulnerable to a session fixation attack. (t0m)

Documentation

Understanding and using sessions.

Modules

Generic Session plugin - ties together server side storage and client side state required to maintain session data.
Base class for session state preservation plugins.
Base class for session storage drivers.
Doesn't really store sessions - useful for tests.
Reusable sanity for session storage engines.