Releases: SoloPHP/Session
Releases · SoloPHP/Session
Release list
v2.0.0
Fixed
- Fixed session timeout bug where sessions were never expiring
resetSession()now properly returns after reset to prevent zombie sessionscheckSessionIntegrity()now properly returns after reset- Cookie is now deleted before session destruction in
resetSession()
Added
getCreatedAt()method to retrieve session creation timestampcreated_attimestamp stored when session is first initiatedexpireOnCloseparameter to control cookie behavior on browser close
Changed
- Simplified configuration - removed redundant
timeoutandgcMaxlifetimeparameters - Renamed
getTimeout()togetLifetime() lifetimeis now the single parameter for idle timeout (in seconds, default: 1800)gc_maxlifetimeis now automatically synced withlifetime- Updated dependencies: PHPUnit ^12.3, PHPStan ^2.1, PHP_CodeSniffer ^3.13
- Improved type safety (PHPStan level 8 compliance)
sameSiteparameter now strictly typed as'Strict'|'Lax'|'None'
Security
- Sessions now properly expire after configured timeout period
- Cookie cleanup guaranteed when session is reset due to timeout or integrity violation
v1.2.0
v1.1.0
Added
- Advanced session security configuration
- Session timeout management (configurable)
- IP and User-Agent validation
- Protection against session fixation
- Configurable cookie security settings (httpOnly, secure, sameSite)
- Environment-specific settings support
- Session monitoring and status methods
- Cookie domain and path configuration
Changed
- Updated PHP requirement to 8.1+ (from 7.4+)
- Constructor now accepts optional configuration parameters
- Added strict type declarations
Backward Compatible Changes
- Basic methods remain unchanged (get, set, has, unset, clear)
- Default configuration matches previous behavior
- No changes required for basic usage