

distrib > Mandriva > 2010.0 > i586 > media > contrib-release > by-pkgid > 8b99df826c3b6cf56a1caaae5f931d50 > files > 614


<?xml version="1.0" encoding="iso-8859-1"?>
<!DOCTYPE html 
     PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"

<html xmlns="" xml:lang="en" lang="en">
  <title>Class: ActionController::Session::CookieStore</title>
  <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
  <meta http-equiv="Content-Script-Type" content="text/javascript" />
  <link rel="stylesheet" href="../../.././rdoc-style.css" type="text/css" media="screen" />
  <script type="text/javascript">
  // <![CDATA[

  function popupCode( url ) {, "Code", "resizable=yes,scrollbars=yes,toolbar=no,status=no,height=150,width=400")

  function toggleCode( id ) {
    if ( document.getElementById )
      elem = document.getElementById( id );
    else if ( document.all )
      elem = eval( "document.all." + id );
      return false;

    elemStyle =;
    if ( elemStyle.display != "block" ) {
      elemStyle.display = "block"
    } else {
      elemStyle.display = "none"

    return true;
  // Make codeblocks hidden by default
  document.writeln( "<style type=\"text/css\">div.method-source-code { display: none }</style>" )
  // ]]>


    <div id="classHeader">
        <table class="header-table">
        <tr class="top-aligned-row">
          <td class="class-name-in-header">ActionController::Session::CookieStore</td>
        <tr class="top-aligned-row">
                <a href="../../../files/lib/action_controller/session/cookie_store_rb.html">
        <br />

        <tr class="top-aligned-row">
                <a href="../../Object.html">
  <!-- banner header -->

  <div id="bodyContent">

  <div id="contextContent">

    <div id="description">
This cookie-based session store is the Rails default. Sessions typically
contain at most a user_id and flash message; both fit within the 4K cookie
size limit. Cookie-based sessions are dramatically faster than the
If you have more than 4K of session data or don&#8216;t want your data to
be visible to the user, pick another session store.
<a href="CookieStore/CookieOverflow.html">CookieOverflow</a> is raised if
you attempt to store more than 4K of data.
A message digest is included with the cookie to ensure data integrity: a
user cannot alter his <tt>user_id</tt> without knowing the secret key
included in the hash. New apps are generated with a pregenerated secret in
config/environment.rb. Set your own for old apps you&#8216;re upgrading.
<a href="../Session.html">Session</a> options:
<li><tt>:secret</tt>: An application-wide key string or block returning a
string called per generated digest. The block is called with the
CGI::Session instance as an argument. It&#8216;s important that the secret
is not vulnerable to a dictionary attack. Therefore, you should choose a
secret consisting of random numbers and letters and more than 30
characters. Examples:

  :secret =&gt; '449fe2e7daee471bffae2fd8dc02313d'
  :secret =&gt; { User.current_user.secret_key }
<li><tt>:digest</tt>: The message digest algorithm used to verify session
integrity defaults to &#8216;SHA1&#8217; but may be any digest provided by
OpenSSL, such as &#8216;MD5&#8217;, &#8216;RIPEMD160&#8217;,
&#8216;SHA256&#8217;, etc.

To generate a secret key for an existing application, run &quot;rake
secret&quot; and set the key in config/environment.rb.
Note that changing digest or secret invalidates all existing sessions!



    <div id="method-list">
      <h3 class="section-bar">Methods</h3>

      <div class="name-list">
      <a href="#M000138">call</a>&nbsp;&nbsp;
      <a href="#M000137">new</a>&nbsp;&nbsp;


    <!-- if includes -->

    <div id="section">

    <div id="class-list">
      <h3 class="section-bar">Classes and Modules</h3>

      Class <a href="CookieStore/CookieOverflow.html" class="link">ActionController::Session::CookieStore::CookieOverflow</a><br />


    <div id="constants-list">
      <h3 class="section-bar">Constants</h3>

      <div class="name-list">
        <table summary="Constants">
        <tr class="top-aligned-row context-row">
          <td class="context-item-name">MAX</td>
          <td class="context-item-value">4096</td>
          <td width="3em">&nbsp;</td>
          <td class="context-item-desc">
<a href="../Cookies.html">Cookies</a> can typically store 4096 bytes.

        <tr class="top-aligned-row context-row">
          <td class="context-item-name">SECRET_MIN_LENGTH</td>
          <td class="context-item-value">30</td>
        <tr class="top-aligned-row context-row">
          <td class="context-item-name">DEFAULT_OPTIONS</td>
          <td class="context-item-value">{         :key          =&gt; '_session_id',         :domain       =&gt; nil,         :path         =&gt; &quot;/&quot;,         :expire_after =&gt; nil,         :httponly     =&gt; true</td>
        <tr class="top-aligned-row context-row">
          <td class="context-item-name">ENV_SESSION_KEY</td>
          <td class="context-item-value">&quot;rack.session&quot;.freeze</td>
        <tr class="top-aligned-row context-row">
          <td class="context-item-name">ENV_SESSION_OPTIONS_KEY</td>
          <td class="context-item-value">&quot;rack.session.options&quot;.freeze</td>
        <tr class="top-aligned-row context-row">
          <td class="context-item-name">HTTP_SET_COOKIE</td>
          <td class="context-item-value">&quot;Set-Cookie&quot;.freeze</td>


    <!-- if method_list -->
    <div id="methods">
      <h3 class="section-bar">Public Class methods</h3>

      <div id="method-M000137" class="method-detail">
        <a name="M000137"></a>

        <div class="method-heading">
          <a href="CookieStore.src/M000137.html" target="Code" class="method-signature"
            onclick="popupCode('CookieStore.src/M000137.html');return false;">
          <span class="method-name">new</span><span class="method-args">(app, options = {})</span>
        <div class="method-description">

      <h3 class="section-bar">Public Instance methods</h3>

      <div id="method-M000138" class="method-detail">
        <a name="M000138"></a>

        <div class="method-heading">
          <a href="CookieStore.src/M000138.html" target="Code" class="method-signature"
            onclick="popupCode('CookieStore.src/M000138.html');return false;">
          <span class="method-name">call</span><span class="method-args">(env)</span>
        <div class="method-description">



<div id="validator-badges">
  <p><small><a href="">[Validate]</a></small></p>
