Search by

componenta / auth-session

Shelamkoff

Authentication-session contracts and lifecycle for Componenta Auth

Package info

github.com/componenta/auth-session

pkg:composer/componenta/auth-session

Statistics

Installs: 14

Dependents: 10

Suggesters: 0

Stars: 0

Open Issues: 0

v1.0.0 2026-09-27 22:32 UTC

This package is auto-updated.

Last update: 2026-09-27 22:46:26 UTC


README

Authentication-session contracts and lifecycle for Componenta Auth 3.

This package owns the logical authenticated session model. It does not depend on componenta/session, HTTP, cookies, Cycle ORM or a database implementation.

Related packages:

  • componenta/auth-session-database — persistent storage.
  • componenta/auth-session-http — browser/HTTP transport, middleware and session-bound CSRF.
  • componenta/auth-session-app — Componenta DI parameter integration.

Session timestamps

AuthSession::$authenticatedAt is the initial successful login time and remains unchanged during credential rotation or reauthentication. reauthenticatedAt and reauthenticationEvidence describe the latest fresh proof; evidence describes the cumulative authentication evidence.

The redundant createdAt constructor argument and property have been removed. Update named calls by removing createdAt: and positional calls by removing the timestamp immediately before authenticatedAt. Pre-authentication transactions still have their own createdAt, because they exist before authentication.