Skip to content

Add support for stateless HTTP sessions - #43

Merged
szeka9 merged 1 commit into
mainfrom
development
Aug 1, 2026
Merged

szeka9 merged 1 commit into
mainfrom
development

Conversation

@szeka9

@szeka9 szeka9 commented Aug 1, 2026

Copy link
Copy Markdown
Owner

Support cryptographically signed session cookies,
without session state on the server. Such cookies
allow more responsive web applications where the
PBKDF2 computation is too expensive per request.

Move the existing CSRF cookie implementation to a
separate module and create a simple adapter module
(pyrobusta.utils.clock) for monotonic time functions
to simplify testing.

Add new configuration keys (http_sessions, http_session_ttl_sec)
for session configuration.

Support cryptographically signed session cookies,
without session state on the server. Such cookies
allow more responsive web applications where the
PBKDF2 computation is too expensive per request.

Move the existing CSRF cookie implementation to a
separate module and create a simple adapter module
(pyrobusta.utils.clock) for monotonic time functions
to simplify testing.

Add new configuration keys (http_sessions, http_session_ttl_sec)
for session configuration.
@szeka9
szeka9 merged commit 4fe3f47 into main Aug 1, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant