Skip to main content

flask-session.manager.sk

Version Python License: MIT

Flask companion package for react-session.manager.sk.

Cookie-driven JWT session management for Flask backends, designed to pair with the React session manager's HttpOnly-cookie transport.

Install

# uv (recommended)
uv add flask-session.manager.sk

# pip
pip install flask-session.manager.sk

Quick Start

from flask import Flask, jsonify
from flask_jwt_extended import create_access_token
from flask_session_manager_sk import SessionManager, SessionManagerCallbacks

app = Flask(__name__)
app.config.update(
    {
        "SECRET_KEY": "your-secret-key",
        "JWT_TOKEN_LOCATION": ["cookies"],
        "JWT_COOKIE_SECURE": True,  # require HTTPS in production
        "JWT_COOKIE_CSRF_PROTECT": True,
        "JWT_ACCESS_COOKIE_NAME": "access_token_cookie",
        "FRONTEND_URL": "https://myapp.example.com",
        "CORS_ORIGINS": ["https://myapp.example.com"],
    }
)

manager = SessionManager()

callbacks = SessionManagerCallbacks(
    user_lookup=lambda identity: get_user_by_id(identity),
    refresh_user_token=lambda user, agent, device_uid: create_and_store_token(
        user, agent, device_uid
    ),
    verify_user_token=lambda user, agent, device_uid, token: user.check_token(
        agent, device_uid, token
    ),
    is_user_active=lambda user: user.is_active,
)

manager.init_app(app, callbacks=callbacks)


@app.route("/auth/who")
@jwt_required(optional=True)
def whoami():
    from flask_jwt_extended import current_user

    if current_user:
        return jsonify(logged_in=True, user_id=current_user.id)
    return jsonify(logged_in=False)

Public API

Only four names are part of the stable surface:

Name Description
SessionManager Flask extension that wires JWT callbacks
SessionManagerCallbacks Frozen dataclass of application hooks
token_response Create a JSON response with an HttpOnly JWT cookie
clear_token_response Create a response that clears JWT cookies

Everything else in the package is internal and may change without notice.

import flask_session_manager_sk

print(flask_session_manager_sk.__version__)  # e.g. "1.0.0"

SessionManagerCallbacks

@dataclass(frozen=True)
class SessionManagerCallbacks:
    # Required
    user_lookup: Callable[[str], Any | None]
    refresh_user_token: Callable[[Any, str, str | None], str | None]

    # Optional
    verify_user_token: Callable[[Any, str | None, str | None], Any | None] | None = None
    is_user_active: Callable[[Any], bool] | None = None

Flask Configuration Reference

These values are read at runtime via current_app.config. No configuration is stored in the package.

Key Required Default Description
SECRET_KEY Yes — Flask secret, must be ≥32 bytes for HMAC-SHA256
JWT_TOKEN_LOCATION Yes — Should include "cookies"
JWT_ACCESS_COOKIE_NAME Yes — Cookie name; react-session.manager.sk expects "access_token_cookie"
JWT_COOKIE_CSRF_PROTECT Yes — Must be True for browser clients
JWT_COOKIE_SECURE Yes — True in production (HTTPS only)
JWT_COOKIE_SAMESITE No — "Lax" or "Strict"
FRONTEND_URL Yes — Canonical URL of the SPA
CORS_ORIGINS Yes — List of allowed browser origins

React Companion Contract

The frontend companion react-session.manager.sk (v4.0+) uses this transport contract:

  • Axios configured with withCredentials: true, withXSRFToken: true
  • Cookies expected at default Flask-JWT-Extended names:
    • access_token_cookie (JWT)
    • csrf_access_token (CSRF double-submit)
  • CSRF header sent as X-CSRF-TOKEN
  • deviceUID header sent on every request
  • appVersion header sent on every request
  • No Authorization bearer header for browser requests
  • Legacy localStorage/sessionStorage bearer tokens are automatically cleared

Internal Modules

Not part of the stable API. Import at your own risk.

Module Content
flask_session_manager_sk.cookies CSRF origin checks, cookie auth detection, clear_session_token_value
flask_session_manager_sk.request get_agent, get_ip, get_token, get_dets_from_request
flask_session_manager_sk.tokens create_token_hash, token_hint, verify_token_hash, update_token_record
flask_session_manager_sk.extension SessionManager implementation details

Migrating from Bearer Tokens

If your backend currently returns access tokens as JSON payloads (e.g. {"access_token": "..."}) and stores them in localStorage:

  1. Package adoption: Wire SessionManager with your user-lookup and token-refresh callbacks.
  2. Login endpoint: Call token_response(payload, status, access_token) instead of jsonify(payload). This sets the HttpOnly cookie automatically.
  3. CSRF check: Add reject_cookie_csrf() as a @app.before_request hook for all unsafe methods (POST, PUT, DELETE).
  4. Frontend: Upgrade react-session.manager.sk to v4.0+. It removes bearer-token browser storage and sends cookie credentials automatically.
  5. Backwards compatibility: Non-browser clients (API scripts, scheduled tasks) can still send Authorization: Bearer <token>. The CSRF check skips bearer-authenticated requests.

Development

git clone https://github.com/Skulldorom/flask-session.manager.sk.git
cd flask-session.manager.sk

# Install deps + editable package
uv sync --dev

# Run checks
uv run ruff check .
uv run ruff format --check .
uv run pytest -v

# Build
uv build

License

MIT — see LICENSE.

Release files for flask-session.manager.sk 1.0.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for flask-session.manager.sk 1.0.4
File Size Uploaded
flask_session_manager_sk-1.0.4.tar.gz 26.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for flask-session.manager.sk 1.0.4
File Interpreter ABI Platform
flask_session_manager_sk-1.0.4-py3-none-any.whl Python 3 none any Details

Total release size: 35.4 kB

Release files / flask_session_manager_sk-1.0.4.tar.gz

Download URL flask_session_manager_sk-1.0.4.tar.gz
Size 26.5 kB
Tags Source
SHA-256 checksum
How to use checksums
8f366780f9923cb984190b6650261809b8c73c3152cd00fb28f2f8e963caa148
BLAKE2b-256 checksum
How to use checksums
67ef82bf55e6221a59ebd483eee2a738bf67667a4b20262cba926024db6ff64c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 5, 2026.

Transparency log

Release files / flask_session_manager_sk-1.0.4-py3-none-any.whl

Download URL flask_session_manager_sk-1.0.4-py3-none-any.whl
Size 8.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3d29d1247e0eae00962bee0338426f0adfd88c8e613ba89e837db183d4e02d6f
BLAKE2b-256 checksum
How to use checksums
11fe5ae8a770eb32aefd0e3f9d28955121abb2667c2a4d22d456cfbfdbdcb58f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 5, 2026.

Transparency log

Release history Release notifications | RSS feed

1.3.2

2 release files

1.3.1

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.9

2 release files

1.0.8

2 release files

1.0.7

2 release files

1.0.6

2 release files

This release

1.0.4 This release

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.0

2 release files

0.1.4

2 release files

0.1.2

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page