Changes for version 0.26 - 2026-08-21

  • `session store => ...` keeps the session server-side and the cookie carries a signed 128-bit id.
  • `$c->session_expire` now REVOKES a stored session: it deletes the entry, so a cookie somebody copied is dead on its next request. Without a store it is unchanged, and still can only ask the browser in front of it to forget.
  • `$c->session_rotate` keeps the session and gives it a new id, deleting the old entry.
  • `session sliding => 1` extends a stored session while it is being used
  • `session tier => $seconds` lets a stored session be read through the cache's memory tier, which it otherwise goes round. The number is how long a revoked session may keep working on a worker that missed the invalidation, so it is capped and checked against the store's own memory_ttl.

Documentation

the Punk command line

Modules

a MVC web framework
the per-application registry and boot compiler
the authentication battery
password hashing
cross-origin resource sharing
single-use CSRF tokens
a pluggable cache with TTL
a cache store on disk, shared by the whole worker pool
an in process cache store, bounded by bytes
the punk command line: registry, dispatcher and commands
YAML configuration with secrets kept out of the file
the per-request object
base class for Punk controllers
the development error page
an async result that runs on the loop, or blocks
scaffold a new Punk application
security response headers
a level-based logger
the storage-agnostic model tier
the default DBI backend for Punk models
a non-blocking backend for Punk models
a directory of markdown as a documentation site
the api mount: spec-first operations
base class for Punk plugins
content addressed storage for uploads
Content-Security-Policy with a per request nonce
ETags and 304s for dynamic responses
liveness and readiness probes that mean different things
Idempotency on unsafe methods
a Prometheus endpoint whose labels cannot run away
give every request an id
sitemap.xml and robots.txt from the route table
rate limiting and IP blocking over Hyperman's shared arena
a lazy wrapper over the PSGI environment
a response builder
the compiled-at-boot route tables (XS)
the handle an under returns
a Server-Sent Events stream
the bounded body of a ranged send_file response
signed cookie sessions
server-side sessions, on any store
serving files from a directory
an in-process test client for Punk applications
a pure-Perl RFC 6455 codec for testing WebSocket servers
the client side of one WebSocket connection
the outbound HTTP agent on the context
an uploaded file from a multipart form
collecting request validation
the Template::Stencil view engine
the pluggable view engine registry (XS)
a WebSocket connection
pub/sub groups of WebSocket connections