ri > ActionDispatch::Session::CookieStore

= ActionDispatch::Session::CookieStore < ActionDispatch::Session::AbstractSecureStore

(from /home/chedong/.local/share/rdoc)
------------------------------------------------------------------------
This cookie-based session store is the Rails default. It is dramatically
faster than the alternatives.

Sessions typically contain at most a user_id and flash message; both fit
within the 4096 bytes cookie size limit. A CookieOverflow exception is
raised if you attempt to store more than 4096 bytes of data.

The cookie jar used for storage is automatically configured to be the
best possible option given your application's configuration.

Your cookies will be encrypted using your apps secret_key_base. This
goes a step further than signed cookies in that encrypted cookies cannot
be altered or read by users. This is the default starting in Rails 4.

Configure your session store in an initializer:

  Rails.application.config.session_store :cookie_store, key: '_your_app_session'

In the development and test environments your application's secret key
base is generated by Rails and stored in a temporary file in
tmp/development_secret.txt. In all other environments, it is stored
encrypted in the config/credentials.yml.enc file.

If your application was not updated to Rails 5.2 defaults, the
secret_key_base will be found in the old config/secrets.yml file.

Note that changing your secret_key_base will invalidate all existing
session. Additionally, you should take care to make sure you are not
relying on the ability to decode signed cookies generated by your app in
external applications or JavaScript before changing it.

Because CookieStore extends Rack::Session::Abstract::Persisted, many of
the options described there can be used to customize the session cookie
that is generated. For example:

  Rails.application.config.session_store :cookie_store, expire_after: 14.days

would set the session cookie to expire automatically 14 days after
creation. Other useful options include :key, :secure and :httponly.
------------------------------------------------------------------------
= Class methods:

  new

= Instance methods:

  delete_session
  load_session

Generated by phpman v4.9.26-1-g511901d · Markdown · JSON · MCP Author: Che Dong Under GNU General Public License
2026-07-29 12:32 @216.73.217.111
CrawledBy Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
Valid XHTML 1.0 Transitional!Valid CSS!