Socket
Socket
Sign inDemoInstall

@brevisstudios/session-from-header

Package Overview
Dependencies
1
Maintainers
1
Versions
4
Alerts
File Explorer

Advanced tools

Install Socket

Detect and block malicious and high-risk dependencies

Install

    @brevisstudios/session-from-header

Although the package has a simple name, it's found to be crucial to properly fetch a client's session if you're using express-session for your session management and want to use a header for your session ID. express-session Only supports fetching a sessio


Version published
Weekly downloads
5
increased by150%
Maintainers
1
Install size
3.53 kB
Created
Weekly downloads
 

Readme

Source

Session from Header

Although the package has a simple name, it's found to be crucial to properly fetch a client's session if you're using express-session for your session management and want to use a header for your session ID. express-session Only supports fetching a session using cookies, but more and more (mobile) clients disallow cookies to be used. If not running into technical limitations, there are other reasons why you'd want to use a header to pass the session ID rather than a cookie.

Usage

The concept is simple. Everything keeps working as it is, but additionally a header of choice is parsed to get the session ID. By default, this is the x-session-id header.

Setup

After installing the module using your package manager of choice, use the middleware right before you use the session middleware. Use the same secret in both middlewares.

// First use this middleware...
app.use(SessionFromHeader({secret: 'mySecret'}));  
  
// ... then the express-session middleware
app.use(session({  
  secret: 'mySecret',
  ...

Configuration

You can pass several options to SessionFromHeader as outlined below with the default values:

{  
  secret: null, // Mandatory, must be the same as the express-session secret
  headerName: 'x-session-id', // Header that is checked for the session ID
  cookieName: 'connect-sid',  // Cookie name, must be the same as the express-session cookie name.
}

FAQs

Last updated on 29 Mar 2024

Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc