NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4699 most downloaded on npm
Simple session middleware for Express
Last release 8 months ago
22 Jan 2026
Ships fairly regularly
a new release about every 8 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
67 releases · first in 2014
Add dynamic cookie options support Cookie options can now be dynamic, allowing for more flexible and context-aware configuration based on each request
Add dynamic cookie options support
Cookie options can now be dynamic, allowing for more flexible and context-aware configuration based on each request. This feature enables programmatic modification of cookie attributes like secure, httpOnly, sameSite, maxAge, domain, and path based on session or request conditions.
var app = express()
app.use(session({
secret: 'keyboard cat',
resave: false,
saveUninitialized: true,
cookie: function (req) {
var match = req.url.match(/^\/([^/]+)/);
return {
path: match ? '/' + match[1] : '/',
httpOnly: true,
secure: req.secure || false,
maxAge: 60000
}
}
}))
Add sameSite 'auto' support for automatic SameSite attribute configuration
Added sameSite: 'auto' option for cookie configuration that automatically sets SameSite=None for HTTPS and SameSite=Lax for HTTP connections, simplifying cookie handling across different environments.
deps: use tilde notation for dependencies
sess parameter from generateSessionId fun… by @Ayoub-Mabrouk in https://github.com/expressjs/session/pull/1001Full Changelog: https://github.com/expressjs/session/compare/v1.18.2...v1.19.0
One column per quarter.
fix: Resolve test failure - Refresh server.crt with existing key extending expiry to Nov 21 03:28:10 2034 GMT by @BaileyFirman in https://github.com/e
Full Changelog: https://github.com/expressjs/session/compare/v1.18.1...v1.18.2
chore: add support for OSSF scorecard reporting by @inigomarquinez in https://github.com/expressjs/session/pull/984
Full Changelog: https://github.com/expressjs/session/compare/v1.18.0...v1.18.1
Add debug log for pathname mismatch
partitioned to cookie optionspriority to cookie optionssecret that crypto.createHmac supportsexpires option to reject invalid datesFix resaving already-saved new session at end of request
Fix res.end patch to always commit headers
res.end patch to always commit headers
Fix internal method wrapping error on failed reloads
* deps: cookie@0.4.0 - Add SameSite=None support * deps: safe-buffer@5.2.0
SameSite=None supportFix restoring cookie.originalMaxAge when store returns Date
cookie.originalMaxAge when store returns Date
Fix error passing data option to Cookie constructor
data option to Cookie constructor
Deprecate setting cookie.maxAge to a Date object
cookie.maxAge value earlier
cookie.maxAge to a Date objectresave: false may not save altered sessionsutils-merge dependencysafe-buffer for improved Buffer APISet-Cookie as cookie header name for compatibilityeval usage with Function constructorprocess to check for listenersres.writeHead patch missing return valueperf: reduce overhead for full URLs
RegExp=Fix TypeError when req.url is an empty string
TypeError when req.url is an empty string
Buffer loadingNothing published for this version
* deps: debug@2.6.7 - deps: ms@2.0.0
* deps: debug@2.6.3 - Fix DEBUG_MAX_ARRAY_LENGTH * deps: uid-safe@~2.1.4 - Remove base64-url dependency
DEBUG_MAX_ARRAY_LENGTHbase64-url dependencyFix deprecation messages in WebStorm and other editors
DEBUG_FD set to 1 or 2Deprecated DEBUG_FD environment variable
Buffer.from when availableDEBUG_FD environment variableFix deprecation warning in Node.js 7.x
Fix not always resetting session max age before session save
sameSite option to actually alter the Set-CookieCorrectly inherit from EventEmitter class in Store base class
EventEmitter class in Store base classSet-Cookie Expires was not always updatedreq.session objectsameSite optionencode is not a functionexpires is not a Daterandom-bytes for byte sourceFix rolling: true to not set cookie when no session exists
rolling: true to not set cookie when no session exists
saveUninitialized: false + rolling: true behaviorFix cookie Max-Age to never be a floating point number
Max-Age to never be a floating point numberSupport the value 'auto' in the cookie.secure option
'auto' in the cookie.secure optionserialize- deps: cookie@0.1.3 - Slight optimizations - deps: crc@3.3.0
- deps: debug@~2.2.0 - deps: ms@0.7.1 - deps: uid-safe@~2.0.0
Fix mutating options.secret value
options.secret valueSupport an array in secret option for key rotation
secret option for key rotationFix high intensity foreground color for bold
Use crypto.randomBytes, if available
crypto.randomBytes, if availableFix error branch that would throw
- deps: uid-safe@1.0.2 - Remove dependency on mz
mzAdd store.touch interface for session stores
store.touch interface for session storesMemoryStore expiration with resave: falseFix error when req.sessionID contains a non-string value
req.sessionID contains a non-string value- deps: crc@3.2.1 - Minor fixes
Remove unnecessary empty write call
Implement DEBUG_FD env variable support
DEBUG_FD env variable supportUse crc instead of buffer-crc32 for speed
crc instead of buffer-crc32 for speedKeep req.session.save non-enumerable
req.session.save non-enumerableDo not resave already-saved session at end of request
Fix exception on res.end(null) calls
res.end(null) calls- Fix parsing original URL - deps: on-headers@~1.0.0 - deps: parseurl@~1.3.0
Fix response end delay for non-chunked responses
Fix res.end patch to call correct upstream res.write
res.end patch to call correct upstream res.writeWork-around v8 generating empty stack traces
Fix exception when global Error.stackTraceLimit is too low
Error.stackTraceLimit is too lowAdd TRACE_DEPRECATION environment variable
next(err) instead of console.errorTRACE_DEPRECATION environment variable--no-deprecation argument--trace-deprecation argumentAdd support for multiple wildcards in namespaces
req.originalUrlFix blank responses for stores with synchronous operations
- Fix resave deprecation message
Fix confusing option deprecation messages
Fix saveUninitialized deprecation message
Add deprecation message to undefined resave option
resave optionsaveUninitialized optionres.end patch to return correct valueres.end patch to handle multiple res.end calls- deps: cookie-signature@1.0.4 - fix for timing attacks
Move hard-to-track-down req.secret deprecation message
req.secret deprecation messageDeprecate integration with cookie-parser middleware
cookie-parser middlewarereq.secretcookie-parser no longer requiredres.cookie no longer requireduid-safe, faster and even less collisionsAdd genid option to generate custom session IDs
genid option to generate custom session IDssaveUninitialized option to control saving uninitialized sessionsunset option to control unsetting req.sessionrand-token by default; reduce collisionsAdd description in package for npmjs.org listing
Integrate with express "trust proxy" by default
Fix resave such that resave: true works
resave such that resave: true worksYour coding agent can read these notes before it upgrades. Set up the MCP server →