JavaScript set cookie max-age

A user session can be stored in two main ways with cookies: on the server or on the client. This module stores the session data on the client within a cookie, while a module like express-session stores only a session identifier on the client within a cookie and stores the session data on the server, typically in a database.

The following points can help you choose which to use:

  • cookie-session does not require any database / resources on the server side, though the total session data cannot exceed the browser’s max cookie size.
  • cookie-session can simplify certain load-balanced scenarios.
  • cookie-session can be used to store a “light” session and include an identifier to look up a database-backed secondary store to reduce database lookups.

Install

This is a Node.js module available through the npm registry. Installation is done using the

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
0 command:

$ npm install cookie-session

API

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))

cookieSession(options)

Create a new cookie session middleware with the provided options. This middleware will attach the property

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
1 to
var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
2, which provides an object representing the loaded session. This session is either a new session if no valid session was provided in the request, or a loaded session from the request.

The middleware will automatically add a

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
3 header to the response if the contents of
var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
4 were altered. Note that no
var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
3 header will be in the response (and thus no session created for a specific user) unless there are contents in the session, so be sure to add something to
var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
4 as soon as you have identifying information to store for the session.

Options

Cookie session accepts these properties in the options object.

name

The name of the cookie to set, defaults to

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
1.

keys

The list of keys to use to sign & verify cookie values, or a configured

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
8 instance. Set cookies are always signed with
var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
9, while the other keys are valid for verification, allowing for key rotation. If a
var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
8 instance is provided, it can be used to change signature parameters like the algorithm of the signature.

secret

A string which will be used as single key if

req.session = null
1 is not provided.

Cookie Options

Other options are passed to

req.session = null
2 and
req.session = null
3 allowing you to control security, domain, path, and signing among other settings.

The options can also contain any of the following (for the full list, see :

  • req.session = null
    
    4: a number representing the milliseconds from
    req.session = null
    
    5 for expiry
  • req.session = null
    
    6: a
    req.session = null
    
    7 object indicating the cookie’s expiration date (expires at the end of session by default).
  • req.session = null
    
    8: a string indicating the path of the cookie (
    req.session = null
    
    9 by default).
  • var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    0: a string indicating the domain of the cookie (no default).
  • var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    1: a boolean or string indicating whether the cookie is a “same site” cookie (
    var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    2 by default). This can be set to
    var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    3,
    var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    4,
    var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    5, or
    var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    6 (which maps to
    var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    3).
  • var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    8: a boolean indicating whether the cookie is only to be sent over HTTPS (
    var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    2 by default for HTTP,
    var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    6 by default for HTTPS). If this is set to
    var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    6 and Node.js is not directly over a TLS connection, be sure to read how to setup Express behind proxies or the cookie may not ever set correctly.
  • var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    // This allows you to set req.session.maxAge to let certain sessions
    // have a different value than the default.
    app.use(function (req, res, next) {
      req.sessionOptions.maxAge = req.session.maxAge || req.sessionOptions.maxAge
      next()
    })
    
    // ... your logic here ...
    
    2: a boolean indicating whether the cookie is only to be sent over HTTP(S), and not made available to client JavaScript (
    var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    6 by default).
  • var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    // This allows you to set req.session.maxAge to let certain sessions
    // have a different value than the default.
    app.use(function (req, res, next) {
      req.sessionOptions.maxAge = req.session.maxAge || req.sessionOptions.maxAge
      next()
    })
    
    // ... your logic here ...
    
    4: a boolean indicating whether the cookie is to be signed (
    var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    6 by default).
  • var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    // This allows you to set req.session.maxAge to let certain sessions
    // have a different value than the default.
    app.use(function (req, res, next) {
      req.sessionOptions.maxAge = req.session.maxAge || req.sessionOptions.maxAge
      next()
    })
    
    // ... your logic here ...
    
    6: a boolean indicating whether to overwrite previously set cookies of the same name (
    var cookieSession = require('cookie-session')
    var express = require('express')
    
    var app = express()
    
    app.set('trust proxy', 1) // trust first proxy
    
    app.use(cookieSession({
      name: 'session',
      keys: ['key1', 'key2']
    }))
    
    app.get('/', function (req, res, next) {
      // Update views
      req.session.views = (req.session.views || 0) + 1
    
      // Write response
      res.end(req.session.views + ' views')
    })
    
    app.listen(3000)
    
    6 by default).

req.session

Represents the session for the given request.

.isChanged

Is

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.set('trust proxy', 1) // trust first proxy

app.use(cookieSession({
  name: 'session',
  keys: ['key1', 'key2']
}))

app.get('/', function (req, res, next) {
  // Update views
  req.session.views = (req.session.views || 0) + 1

  // Write response
  res.end(req.session.views + ' views')
})

app.listen(3000)
6 if the session has been changed during the request.

.isNew

Is

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.set('trust proxy', 1) // trust first proxy

app.use(cookieSession({
  name: 'session',
  keys: ['key1', 'key2']
}))

app.get('/', function (req, res, next) {
  // Update views
  req.session.views = (req.session.views || 0) + 1

  // Write response
  res.end(req.session.views + ' views')
})

app.listen(3000)
6 if the session is new.

.isPopulated

Determine if the session has been populated with data or is empty.

req.sessionOptions

Represents the session options for the current request. These options are a shallow clone of what was provided at middleware construction and can be altered to change cookie setting behavior on a per-request basis.

Destroying a session

To destroy a session simply set it to

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: ['key1', 'key2']
}))

// Update a value in the cookie so that the set-cookie will be sent.
// Only changes every minute so that it's not sent with every request.
app.use(function (req, res, next) {
  req.session.nowInMinutes = Math.floor(Date.now() / 60e3)
  next()
})

// ... your logic here ...
0:

req.session = null

Saving a session

Since the entire contents of the session is kept in a client-side cookie, the session is “saved” by writing a cookie out in a

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
3 response header. This is done automatically if there has been a change made to the session when the Node.js response headers are being written to the client and the session was not destroyed.

Examples

Simple view counter example

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.set('trust proxy', 1) // trust first proxy

app.use(cookieSession({
  name: 'session',
  keys: ['key1', 'key2']
}))

app.get('/', function (req, res, next) {
  // Update views
  req.session.views = (req.session.views || 0) + 1

  // Write response
  res.end(req.session.views + ' views')
})

app.listen(3000)

Per-user sticky max age

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.set('trust proxy', 1) // trust first proxy

app.use(cookieSession({
  name: 'session',
  keys: ['key1', 'key2']
}))

// This allows you to set req.session.maxAge to let certain sessions
// have a different value than the default.
app.use(function (req, res, next) {
  req.sessionOptions.maxAge = req.session.maxAge || req.sessionOptions.maxAge
  next()
})

// ... your logic here ...

Extending the session expiration

This module does not send a

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
3 header if the contents of the session have not changed. This means that to extend the expiration of a session in the user’s browser (in response to user activity, for example) some kind of modification to the session needs be made.

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: ['key1', 'key2']
}))

// Update a value in the cookie so that the set-cookie will be sent.
// Only changes every minute so that it's not sent with every request.
app.use(function (req, res, next) {
  req.session.nowInMinutes = Math.floor(Date.now() / 60e3)
  next()
})

// ... your logic here ...

Using a custom signature algorithm

This example shows creating a custom

var cookieSession = require('cookie-session')
var express = require('express')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: [/* secret keys */],

  // Cookie Options
  maxAge: 24 * 60 * 60 * 1000 // 24 hours
}))
8 instance as the
req.session = null
1 option to provide keys and additional signature configuration.

var cookieSession = require('cookie-session')
var express = require('express')
var Keygrip = require('keygrip')

var app = express()

app.use(cookieSession({
  name: 'session',
  keys: new Keygrip(['key1', 'key2'], 'SHA384', 'base64')
}))

// ... your logic here ...

Usage Limitations

Because the entire session object is encoded and stored in a cookie, it is possible to exceed the maximum cookie size limits on different browsers. The recommends that a browser SHOULD allow

At least 4096 bytes per cookie (as measured by the sum of the length of the cookie’s name, value, and attributes)

In practice this limit differs slightly across browsers. See a list of browser limits here. As a rule of thumb don’t exceed 4093 bytes per domain.

If your session object is large enough to exceed a browser limit when encoded, in most cases the browser will refuse to store the cookie. This will cause the following requests from the browser to either a) not have any session information or b) use old session information that was small enough to not exceed the cookie limit.

If you find your session object is hitting these limits, it is best to consider if data in your session should be loaded from a database on the server instead of transmitted to/from the browser with every request. Or move to an

The setMaxAge(long expiry)method of Java HttpCookie class is used to set the maximum age of the cookie within seconds. The result with a positive value indicates that the cookie will expire after the specified time in seconds.
When cookies are set with an explicit Expires/Max-Age attribute the value will now be capped to no more than 400 days in the future. Previously, there was no limit and cookies could expire as much as multiple millennia in the future.
Quick Answer:.
Expires sets an expiry date for when a cookie gets deleted..
Max-age sets the time in seconds for when a cookie will be deleted (use this, it's no longer 2009).
Internet Explorer (ie6, ie7, and ie8) does not support “max-age”, while (mostly) all browsers support expires..
To delete a cookie, simply rename it using the same name , specifying an empty value, or setting its max-age attribute to 0. document. cookie = "UserName=; max-age=0"; You'll need to include the cookie's path and domain property when deleting it if you had specified them.