componenta / auth-session-database
Cycle Database persistence for Componenta authentication sessions
Package info
github.com/componenta/auth-session-database
pkg:composer/componenta/auth-session-database
Requires
- php: ^8.4
- componenta/auth: ^3.0
- componenta/auth-session: ^1.0
- componenta/identity: ^1.0.1
- cycle/database: ^2.22
- psr/clock: ^1.0
Requires (Dev)
- componenta/clock: ^1.1.0
- phpstan/phpstan: ^2.1
- phpunit/phpunit: ^12.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-27 22:46:36 UTC
README
Cycle Database persistence for componenta/auth-session.
Security properties:
- raw
SessionCredentialvalues are never stored; - credential lookup uses domain-separated HMAC-SHA-256 with key IDs;
- rotation updates one stable session UUID/generation atomically;
- replaced credential hashes become short-lived revocation-only tombstones;
- tombstones never authenticate and exist only for stale logout/revocation races;
- create/revoke-all operations serialize through a per-subject lock row.
Authentication timestamps and schema
The installation schemas use authenticated_at as the initial login time.
The session model, persistence, and oldest-session ordering all use this value;
credential rotation preserves it. There is no auth_sessions.created_at column.
The independent created_at of pre-authentication transactions is retained.
This is the first stable schema for this package. Applications using an earlier
development snapshot must regenerate their application-owned schema migration
to remove auth_sessions.created_at before adopting the new adapter. Preserve
authenticated_at and all other session data. The package does not run migrations
or modify an application's database on installation.