fix: persist admin sessions in DB so deploys don't log out users

Store PHP sessions in the `sessions` MySQL table (30-day TTL) instead of
server files, which disappear on container restart / redeploy.
Cookie lifetime also extended to 30 days.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Lizandro Guarnizo
2026-06-30 18:42:33 -05:00
co-authored by Claude Sonnet 4.6
parent b288b07ff5
commit 37eef6a705
2 changed files with 42 additions and 1 deletions
+4 -1
View File
@@ -1,13 +1,16 @@
<?php
declare(strict_types=1);
require_once __DIR__ . '/DbSessionHandler.php';
class SessionAuth
{
public static function start(): void
{
if (session_status() === PHP_SESSION_NONE) {
session_set_save_handler(new DbSessionHandler(), true);
session_set_cookie_params([
'lifetime' => 0,
'lifetime' => 86400 * 30, // 30 days — survives deploys
'path' => '/',
'secure' => isset($_SERVER['HTTPS']),
'httponly' => true,