Files
kaya/packages/kaya-session
woggioni 3ebf079533 Refactor to composable KayaMixin architecture
Replace wrapper-based SessionMiddleware/OIDCApp with KayaMixin subclasses
applied via KayaApp(mixins=[...]). Mixins hook into handle_request and
handle_websocket via before/after hooks, so both ASGI and RSGI keep working.
Mixin dependencies are applied automatically and deduplicated.
2026-07-23 22:09:59 +08:00
..

kaya-session

Session management for the Kaya web framework.

Provides server-side, identity-agnostic HTTP sessions via a session cookie. The session data is accessible from request handlers as ctx.session.

Usage

from kaya.core import KayaApp, HttpContext
from kaya.session import SessionMixin, InMemorySessionStore

session = SessionMixin(InMemorySessionStore())
app = KayaApp(mixins=[session])

@app.GET('/')
async def home(ctx: HttpContext):
    n = ctx.session.get('visits', 0) + 1
    ctx.session['visits'] = n
    await ctx.send_str(200, f'visits: {n}')

Sessions are created lazily: a cookie is only set when the handler modifies the session.

SessionMixin is a KayaMixin, so the app stays a KayaApp and both ASGI and RSGI keep working.

Session expiry

The cookie sent to the browser has a Max-Age (default 14 days), but that is only a client-side hint. The real boundary is the store's server-side TTL, which the mixin keeps in sync with the cookie Max-Age.

For InMemorySessionStore, a session expires if it is idle for longer than max_age. Active sessions have their expiry slid forward on every access, so a user that keeps visiting stays logged in. If the client ignores the cookie's Max-Age and replays an old cookie value, the store rejects the expired session and creates a fresh empty one.

Set max_age=None to disable server-side expiry (and the Max-Age cookie attribute) entirely.

Features

  • Session: dict-like session object with modification tracking
  • SessionStore: abstract store interface
  • InMemorySessionStore: simple in-memory store for development/single-process
  • SessionMixin: composable Kaya mixin managing session cookies and persistence
  • Session ID regeneration (session.regenerate_id()) and invalidation (session.invalidate()) for authentication layers

Notes

  • InMemorySessionStore does not survive process restarts and is not shared across processes. Production deployments should use a store backed by a shared storage system (planned).