2007-01-22 14:43:50 +01:00
|
|
|
module ActionController #:nodoc:
|
|
|
|
module SessionManagement #:nodoc:
|
|
|
|
def self.included(base)
|
2007-12-21 08:48:59 +01:00
|
|
|
base.class_eval do
|
|
|
|
extend ClassMethods
|
|
|
|
end
|
2007-01-22 14:43:50 +01:00
|
|
|
end
|
|
|
|
|
|
|
|
module ClassMethods
|
2008-05-18 06:22:34 +02:00
|
|
|
# Set the session store to be used for keeping the session data between requests.
|
|
|
|
# By default, sessions are stored in browser cookies (<tt>:cookie_store</tt>),
|
|
|
|
# but you can also specify one of the other included stores (<tt>:active_record_store</tt>,
|
2009-02-04 21:26:08 +01:00
|
|
|
# <tt>:mem_cache_store</tt>, or your own custom class.
|
2007-01-22 14:43:50 +01:00
|
|
|
def session_store=(store)
|
2009-02-04 21:26:08 +01:00
|
|
|
if store == :active_record_store
|
|
|
|
self.session_store = ActiveRecord::SessionStore
|
|
|
|
else
|
|
|
|
@@session_store = store.is_a?(Symbol) ?
|
|
|
|
Session.const_get(store.to_s.camelize) :
|
|
|
|
store
|
|
|
|
end
|
2007-01-22 14:43:50 +01:00
|
|
|
end
|
|
|
|
|
|
|
|
# Returns the session store class currently used.
|
|
|
|
def session_store
|
2009-02-04 21:26:08 +01:00
|
|
|
if defined? @@session_store
|
|
|
|
@@session_store
|
|
|
|
else
|
|
|
|
Session::CookieStore
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def session=(options = {})
|
|
|
|
self.session_store = nil if options.delete(:disabled)
|
|
|
|
session_options.merge!(options)
|
2007-01-22 14:43:50 +01:00
|
|
|
end
|
|
|
|
|
|
|
|
# Returns the hash used to configure the session. Example use:
|
|
|
|
#
|
2009-02-04 21:26:08 +01:00
|
|
|
# ActionController::Base.session_options[:secure] = true # session only available over HTTPS
|
2007-01-22 14:43:50 +01:00
|
|
|
def session_options
|
2009-02-04 21:26:08 +01:00
|
|
|
@session_options ||= {}
|
2007-01-22 14:43:50 +01:00
|
|
|
end
|
|
|
|
|
2009-02-04 21:26:08 +01:00
|
|
|
def session(*args)
|
|
|
|
ActiveSupport::Deprecation.warn(
|
|
|
|
"Disabling sessions for a single controller has been deprecated. " +
|
|
|
|
"Sessions are now lazy loaded. So if you don't access them, " +
|
|
|
|
"consider them off. You can still modify the session cookie " +
|
|
|
|
"options with request.session_options.", caller)
|
2007-01-22 14:43:50 +01:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|