Registry / web-framework / flask-session

flask-session

JSON →
library0.8.0pypypi✓ verified 35d ago

Flask-Session is an official extension for Flask that provides support for server-side session management. Instead of storing session data directly in client-side cookies (which can be size-limited and less secure), it stores it on the server using various backends like Redis, Memcached, FileSystem, MongoDB, SQLAlchemy, or DynamoDB. The current version is 0.8.0, and it is actively maintained by the Pallets organization, ensuring regular updates and compatibility with Flask. [1, 5, 15, 16]

web-frameworkdatabase
Install & Compatibility
Where this runs
tested against v0.8.0 · pip install
no network on importno background threads
Install × environment matrix
Each cell = how many times install + import succeeded across repeated harness runs. Partial = flaky.
glibc = Debian/Ubuntu slim · musl = Alpine Linux
musl
py 3.103.960 runs
installs and imports cleanly · install 0.0s · import 0.000s · 23.5MB
glibc
py 3.103.960 runs
installs and imports cleanly · install 2.4s · import 0.000s · 24MB
22MB installed
● package 22MB
Code
Verified usage

Verified import paths — ran on the pinned version, not inferred.

from flask_session import Session

The 'Session' class from 'flask_session' is for initializing the extension; the 'session' proxy object for accessing/modifying session data comes from 'flask' itself, just like Flask's built-in session. [3, 4]

from flask import session

This quickstart demonstrates how to set up Flask-Session with a Redis backend. It configures the Flask application with a secret key (essential for session security) and specifies Redis as the session storage type. The example includes simple routes to set, get, and clear session data, showcasing how `flask.session` is used once `flask_session.Session` is initialized. Remember to install `redis` (`pip install 'flask-session[redis]'`) for this example to work. [3, 8]

import os from flask import Flask, session, redirect, url_for from flask_session import Session from redis import Redis app = Flask(__name__) # Configuration for server-side sessions app.config["SECRET_KEY"] = os.environ.get("FLASK_SECRET_KEY", "super-secret-key-that-should-be-random-and-long") app.config["SESSION_TYPE"] = "redis" app.config["SESSION_PERMANENT"] = False # Set to True for permanent sessions # Configure Redis client (replace with your Redis connection details) # For production, consider using environment variables for host/port/password app.config["SESSION_REDIS"] = Redis(host=os.environ.get("REDIS_HOST", "localhost"), port=6379, db=0) # Initialize Flask-Session Session(app) @app.route('/') def index(): if 'username' in session: return f'Hello, {session["username"]}! <a href="/logout">Logout</a>' return 'You are not logged in. <a href="/login">Login</a>' @app.route('/login') def login(): # Simulate a login, in a real app this would involve forms and authentication session['username'] = 'testuser' return redirect(url_for('index')) @app.route('/logout') def logout(): session.pop('username', None) return redirect(url_for('index')) if __name__ == '__main__': app.run(debug=True)
Debug
Known footguns
breakingThe default session serialization format changed from `pickle` to `msgspec` in version 0.7.0. While 0.7.0 attempts to convert existing `pickle` sessions upon read/write, `pickle` support will be entirely removed in version 1.0.0. Any un-migrated `pickle` sessions will be cleared upon access in 1.0.0. [5, 7, 10]
deprecatedThe `SESSION_USE_SIGNER` configuration option and `FileSystemSessionInterface` were deprecated in version 0.7.0. `FileSystemSessionInterface` is replaced by `CacheLibSessionInterface` which uses `cachelib` under the hood. [7, 10]
gotchaIt is crucial to set `app.config["SECRET_KEY"]` when using Flask-Session, even though sessions are server-side. This secret key is used to cryptographically sign the session ID cookie that is sent to the client, preventing tampering and ensuring session integrity. [8, 12]
gotchaFlask-Session's `Session` class is for initializing the extension with your Flask application. To access or modify the current session data within your routes, you must import and use `flask.session`, which is Flask's built-in session proxy. Attempting to use the `Session` instance directly for data access will not work as expected. [3, 4]
gotchaThe `PERMANENT_SESSION_LIFETIME` configured in Flask's app config (e.g., `app.config['PERMANENT_SESSION_LIFETIME'] = timedelta(minutes=30)`) is used by Flask-Session to set the expiration time for the *server-side session data*, not just the client-side cookie. This applies regardless of whether `SESSION_PERMANENT` is set to `True` or `False`. [2, 10]
gotchaFlask-Session does not provide a native `dynamodb` session interface or a `[dynamodb]` installation extra. Requesting `flask-session[dynamodb]` will result in a pip warning that the extra is not provided. If you need DynamoDB support, you may need to use a separate extension or implement a custom session interface.
Upgrade
Version history

Breaking-change detection hasn't run for this library yet.

Audit
Security & dependencies

CVE tracking and dependency tree are planned for a later release.

Agent activity
15 hits · last 30 days
gptbot
4
claudebot
4
ahrefsbot
3
Resources