Session Proxy Examples
Edit this pageWarning: You are browsing the documentation for Symfony 3.1, which is no longer maintained.
Consider upgrading your projects to Symfony 7.0.
Session Proxy Examples
The session proxy mechanism has a variety of uses and this article demonstrates two common uses. Rather than using the regular session handler, you can create a custom save handler just by defining a class that extends the SessionHandlerProxy class.
Then, define a new service related to the custom session handler:
1 2 3 4
# app/config/services.yml
services:
app.session_handler:
class: AppBundle\Session\CustomSessionHandler
1 2 3 4 5 6 7 8 9 10 11
<!-- app/config/services.xml -->
<?xml version="1.0" encoding="UTF-8" ?>
<container xmlns="http://symfony.com/schema/dic/services"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://symfony.com/schema/dic/services
http://symfony.com/schema/dic/services/services-1.0.xsd">
<services>
<service id="app.session_handler" class="AppBundle\Session\CustomSessionHandler" />
</services>
</container>
1 2 3 4
// app/config/config.php
use AppBundle\Session\CustomSessionHandler;
$container->register('app.session_handler', CustomSessionHandler::class);
Finally, use the framework.session.handler_id
configuration option to tell
Symfony to use your own session handler instead of the default one:
1 2 3 4 5
# app/config/config.yml
framework:
session:
# ...
handler_id: app.session_handler
1 2 3 4 5 6 7 8 9 10
<!-- app/config/config.xml -->
<?xml version="1.0" encoding="UTF-8" ?>
<container xmlns="http://symfony.com/schema/dic/services"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://symfony.com/schema/dic/services
http://symfony.com/schema/dic/services/services-1.0.xsd">
<framework:config>
<framework:session handler-id="app.session_handler" />
</framework:config>
</container>
1 2 3 4 5 6 7 8
// app/config/config.php
$container->loadFromExtension('framework', array(
// ...
'session' => array(
// ...
'handler_id' => 'app.session_handler',
),
));
Keep reading the next sections to learn how to use the session handlers in practice to solve two common use cases: encrypt session information and define readonly guest sessions.
Encryption of Session Data
If you wanted to encrypt the session data, you could use the proxy to encrypt and decrypt the session as required:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
// src/AppBundle/Session/EncryptedSessionProxy.php
namespace AppBundle\Session;
use Symfony\Component\HttpFoundation\Session\Storage\Proxy\SessionHandlerProxy;
class EncryptedSessionProxy extends SessionHandlerProxy
{
private $key;
public function __construct(\SessionHandlerInterface $handler, $key)
{
$this->key = $key;
parent::__construct($handler);
}
public function read($id)
{
$data = parent::read($id);
return mcrypt_decrypt(\MCRYPT_3DES, $this->key, $data);
}
public function write($id, $data)
{
$data = mcrypt_encrypt(\MCRYPT_3DES, $this->key, $data);
return parent::write($id, $data);
}
}
Readonly Guest Sessions
There are some applications where a session is required for guest users, but where there is no particular need to persist the session. In this case you can intercept the session before it is written:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26
// src/AppBundle/Session/ReadOnlySessionProxy.php
namespace AppBundle\Session;
use AppBundle\Entity\User;
use Symfony\Component\HttpFoundation\Session\Storage\Proxy\SessionHandlerProxy;
class ReadOnlySessionProxy extends SessionHandlerProxy
{
private $user;
public function __construct(\SessionHandlerInterface $handler, User $user)
{
$this->user = $user;
parent::__construct($handler);
}
public function write($id, $data)
{
if ($this->user->isGuest()) {
return;
}
return parent::write($id, $data);
}
}