wai-session-mysql-0.2.1.0: MySQL backed Wai session store

Copyright(C) 2016 Li Meng Jun
LicenseBSD3
MaintainerLi Meng Jun <lmjubuntu@gmail.com>
Stabilityexperimental
Portabilityportable
Safe HaskellNone
LanguageHaskell2010

Network.Wai.Session.MySQL

Description

Simple MySQL backed wai-session backend. This module allows you to store session data of wai-sessions in a MySQL database. Two tables are kept, one to store the session's metadata and one to store key,value pairs for each session. All keys and values are stored as bytea values in the mysql database using haskell's cereal module to serialize and deserialize them.

Please note that the module does not let you configure the names of the database tables. It is recommended to use this module with its own database schema.

Synopsis

Documentation

dbStore :: (WithMySQLConn a, Serialize k, Eq k, Serialize v, MonadIO m) => a -> StoreSettings -> IO (SessionStore m k v) Source #

Create a new mysql backed wai session store.

clearSession :: WithMySQLConn a => a -> ByteString -> Request -> IO () Source #

This function can be called to invalidate a session and enforce creating a new one with a new session ID. It should be called *before* any calls to sessionStore are made. It needs to be passed a request and the cookie name explicitly due to the limited nature of the Network.Wai.Session interface. Sessions should be cleared when a login is performed, to prevent certain kinds of session hijacking attacks.

defaultSettings :: StoreSettings Source #

Create default settings using a session timeout of one hour, a cryptographically secure session id generator using 24 bytes of entropy and putStrLn to log events to stdout.

fromSimpleConnection :: Connection -> IO SimpleConnection Source #

Prepare a simple mysql connection for use by the mysql session store. This basically wraps the connection along with a mutex to ensure transactions work correctly. Connections used this way must not be used anywhere else for the duration of the session store! It is recommended to use a connection pool instead. To use a connection pool, you simply need to implement the WithMySQLConn type class.

purgeOldSessions :: WithMySQLConn a => a -> StoreSettings -> IO Int64 Source #

Delete expired sessions from the database.

purger :: WithMySQLConn a => a -> StoreSettings -> IO ThreadId Source #

Run a thread using forkIO that runs periodically to purge old sessions.

ratherSecureGen :: Int -> IO ByteString Source #

Generate a session ID with n bytes of entropy

data SimpleConnection Source #

A simple MySQL connection stored together with a mutex that prevents from running more than one mysql transaction at the same time. It is recommended to use a connection pool instead for larger sites.

data StoreSettings Source #

These settings control how the session store is behaving

Constructors

StoreSettings 

Fields

  • storeSettingsSessionTimeout :: Int64

    The number of seconds a session is valid Seconds are counted since the session is last accessed (read or written), not since it was created.

  • storeSettingsKeyGen :: IO ByteString

    A random session key generator. The session ID should provide sufficient entropy, and must not be predictable. It is recommended to use a cryptographically secure random number generator.

  • storeSettingsCreateTable :: Bool

    Whether to create the database table if it does not exist upon creating the session store. If set to false, the database table must exist or be created by some other means.

  • storeSettingsLog :: String -> IO ()

    A function that is called by to log events such as session purges or the table creation.

  • storeSettingsPurgeInterval :: Int

    The number of microseconds to sleep between two runs of the old session purge worker.

class WithMySQLConn a where Source #

By default, you pass a mysql connection to the session store when creating it. The passed connection will have to stay open for the (possibly very long) existence of the session and it should not be used for any other purpose during that time. You can implement an instance of this class for a connection pool instead, so that the session manager will not require a permanent open MySQL connection.

Minimal complete definition

withMySQLConn

Methods

withMySQLConn :: a -> (Connection -> IO b) -> IO b Source #

Call the function (Connection -> IO b) with a valid and open MySQL connection.