Databasev0.1.7
@tekir/session
Session management with signed cookies, flash messages, and pluggable stores.
Installation
$
bun add @tekir/sessionFeatures
- Memory, Redis, and database session stores
- Flash messages for one-time data
- get/put/has/pull/forget/clear API
- Session regeneration and destroy
- Signed cookie-based session IDs
- Configurable TTL and cookie options
Quick Example
TypeScript
import { session } from '@tekir/session'
// Register as middleware
app.router.use(session({ cookieName: 'sid', age: 7200 }))
// In a route handler
ctx.session.put('cart', [1, 2, 3])
ctx.session.flash('success', 'Item added!')Changelog
v0.1.7LatestSeptember 16, 2026
- Session middleware and database storage now honor real Tekir response contexts and expiry semantics consistently.
- Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.6July 23, 2026
- Package metadata now follows the shared compatible
0.1.xdependency range used by this coordinated Tekir release.
v0.1.5July 16, 2026
- Regenerated session cookies are emitted through every supported response sink, store TTL semantics are consistent, and session/store errors no longer disappear silently.
v0.1.4June 13, 2026
- Session cookies are now
HttpOnly+SameSite=Lax+Secureby default.Securedefaults totruein production (and whenNODE_ENVis unset); setcookie.secure: falseto opt out explicitly. - A regenerated session ID is now emitted reliably through whichever response sink is available, and it is an error to regenerate when no sink exists, so a new ID can never be silently dropped.
put/flashnow reject__proto__,constructor, andprototypekeys, closing a prototype pollution vector.- The memory store now evicts expired and over-cap entries via a periodic sweep (default 60 s, unref'd) and a
maxEntriesbound (default 100k), with astop()for clean shutdown. Touching an existing session re-syncs its store TTL with the re-sent cookieMax-Age. - Found and fixed with Fable.
v0.1.3May 8, 2026
Session.get<T>defaultsTtoanyinstead ofunknown. Reading session data no longer needs a redundant cast or type guard for the common case (session.get('user')is usable directly). Pass an explicit type when narrowing matters:session.get<UserId>('userId').
v0.1.2April 29, 2026
- Memory and database session stores type-check cleanly without
@tekir/redisinstalled. The redis store loads only when the redis driver is selected.