Releases
v2.0.0
Compare
Sorry, something went wrong.
No results found
Fixed
Fixed session timeout bug where sessions were never expiring
resetSession() now properly returns after reset to prevent zombie sessions
checkSessionIntegrity() now properly returns after reset
Cookie is now deleted before session destruction in resetSession()
Added
getCreatedAt() method to retrieve session creation timestamp
created_at timestamp stored when session is first initiated
expireOnClose parameter to control cookie behavior on browser close
Changed
Simplified configuration - removed redundant timeout and gcMaxlifetime parameters
Renamed getTimeout() to getLifetime()
lifetime is now the single parameter for idle timeout (in seconds, default: 1800)
gc_maxlifetime is now automatically synced with lifetime
Updated dependencies: PHPUnit ^12.3, PHPStan ^2.1, PHP_CodeSniffer ^3.13
Improved type safety (PHPStan level 8 compliance)
sameSite parameter now strictly typed as 'Strict'|'Lax'|'None'
Security
Sessions now properly expire after configured timeout period
Cookie cleanup guaranteed when session is reset due to timeout or integrity violation
You can’t perform that action at this time.