tekir
All Packages
Databasev0.1.7

@tekir/session

Session management with signed cookies, flash messages, and pluggable stores.

Installation

$bun add @tekir/session

Features

  • Memory, Redis, and database session stores
  • Flash messages for one-time data
  • get/put/has/pull/forget/clear API
  • Session regeneration and destroy
  • Signed cookie-based session IDs
  • Configurable TTL and cookie options

Quick Example

TypeScript
import { session } from '@tekir/session'

// Register as middleware
app.router.use(session({ cookieName: 'sid', age: 7200 }))

// In a route handler
ctx.session.put('cart', [1, 2, 3])
ctx.session.flash('success', 'Item added!')

Changelog

v0.1.7LatestSeptember 16, 2026
  • Session middleware and database storage now honor real Tekir response contexts and expiry semantics consistently.
  • Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.6July 23, 2026
  • Package metadata now follows the shared compatible 0.1.x dependency range used by this coordinated Tekir release.
v0.1.5July 16, 2026
  • Regenerated session cookies are emitted through every supported response sink, store TTL semantics are consistent, and session/store errors no longer disappear silently.
v0.1.4June 13, 2026
  • Session cookies are now HttpOnly + SameSite=Lax + Secure by default. Secure defaults to true in production (and when NODE_ENV is unset); set cookie.secure: false to opt out explicitly.
  • A regenerated session ID is now emitted reliably through whichever response sink is available, and it is an error to regenerate when no sink exists, so a new ID can never be silently dropped.
  • put/flash now reject __proto__, constructor, and prototype keys, closing a prototype pollution vector.
  • The memory store now evicts expired and over-cap entries via a periodic sweep (default 60 s, unref'd) and a maxEntries bound (default 100k), with a stop() for clean shutdown. Touching an existing session re-syncs its store TTL with the re-sent cookie Max-Age.
  • Found and fixed with Fable.
v0.1.3May 8, 2026
  • Session.get<T> defaults T to any instead of unknown. Reading session data no longer needs a redundant cast or type guard for the common case (session.get('user') is usable directly). Pass an explicit type when narrowing matters: session.get<UserId>('userId').
v0.1.2April 29, 2026
  • Memory and database session stores type-check cleanly without @tekir/redis installed. The redis store loads only when the redis driver is selected.

Other Database packages