componenta / auth-session
Authentication-session contracts and lifecycle for Componenta Auth
Requires
- php: ^8.4
- componenta/auth: ^3.0
- componenta/identity: ^1.0.1
Requires (Dev)
- phpstan/phpstan: ^2.1
- phpunit/phpunit: ^12.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-27 22:46:26 UTC
README
Authentication-session contracts and lifecycle for Componenta Auth 3.
This package owns the logical authenticated session model. It does not depend
on componenta/session, HTTP, cookies, Cycle ORM or a database implementation.
Related packages:
componenta/auth-session-database— persistent storage.componenta/auth-session-http— browser/HTTP transport, middleware and session-bound CSRF.componenta/auth-session-app— Componenta DI parameter integration.
Session timestamps
AuthSession::$authenticatedAt is the initial successful login time and remains
unchanged during credential rotation or reauthentication. reauthenticatedAt
and reauthenticationEvidence describe the latest fresh proof; evidence
describes the cumulative authentication evidence.
The redundant createdAt constructor argument and property have been removed.
Update named calls by removing createdAt: and positional calls by removing the
timestamp immediately before authenticatedAt. Pre-authentication transactions
still have their own createdAt, because they exist before authentication.