flask-session.manager.sk
Flask companion package for react-session.manager.sk.
Cookie-driven JWT session management for Flask backends, designed to pair with the React session manager's HttpOnly-cookie transport.
Install
# uv (recommended)
uv add flask-session.manager.sk
# pip
pip install flask-session.manager.sk
Quick Start
from flask import Flask, jsonify
from flask_jwt_extended import create_access_token
from flask_session_manager_sk import SessionManager, SessionManagerCallbacks
app = Flask(__name__)
app.config.update(
{
"SECRET_KEY": "your-secret-key",
"JWT_TOKEN_LOCATION": ["cookies"],
"JWT_COOKIE_SECURE": True, # require HTTPS in production
"JWT_COOKIE_CSRF_PROTECT": True,
"JWT_ACCESS_COOKIE_NAME": "access_token_cookie",
"FRONTEND_URL": "https://myapp.example.com",
"CORS_ORIGINS": ["https://myapp.example.com"],
}
)
manager = SessionManager()
callbacks = SessionManagerCallbacks(
user_lookup=lambda identity: get_user_by_id(identity),
refresh_user_token=lambda user, agent, device_uid: create_and_store_token(
user, agent, device_uid
),
verify_user_token=lambda user, agent, device_uid, token: user.check_token(
agent, device_uid, token
),
is_user_active=lambda user: user.is_active,
)
manager.init_app(app, callbacks=callbacks)
@app.route("/auth/who")
@jwt_required(optional=True)
def whoami():
from flask_jwt_extended import current_user
if current_user:
return jsonify(logged_in=True, user_id=current_user.id)
return jsonify(logged_in=False)
Public API
Only four names are part of the stable surface:
| Name | Description |
|---|---|
SessionManager |
Flask extension that wires JWT callbacks |
SessionManagerCallbacks |
Frozen dataclass of application hooks |
token_response |
Create a JSON response with an HttpOnly JWT cookie |
clear_token_response |
Create a response that clears JWT cookies |
Everything else in the package is internal and may change without notice.
import flask_session_manager_sk
print(flask_session_manager_sk.__version__) # e.g. "1.0.0"
SessionManagerCallbacks
@dataclass(frozen=True)
class SessionManagerCallbacks:
# Required
user_lookup: Callable[[str], Any | None]
refresh_user_token: Callable[[Any, str, str | None], str | None]
# Optional
verify_user_token: Callable[[Any, str | None, str | None], Any | None] | None = None
is_user_active: Callable[[Any], bool] | None = None
Flask Configuration Reference
These values are read at runtime via current_app.config. No configuration is
stored in the package.
| Key | Required | Default | Description |
|---|---|---|---|
SECRET_KEY |
Yes | — | Flask secret, must be ≥32 bytes for HMAC-SHA256 |
JWT_TOKEN_LOCATION |
Yes | — | Should include "cookies" |
JWT_ACCESS_COOKIE_NAME |
Yes | — | Cookie name; react-session.manager.sk expects "access_token_cookie" |
JWT_COOKIE_CSRF_PROTECT |
Yes | — | Must be True for browser clients |
JWT_COOKIE_SECURE |
Yes | — | True in production (HTTPS only) |
JWT_COOKIE_SAMESITE |
No | — | "Lax" or "Strict" |
FRONTEND_URL |
Yes | — | Canonical URL of the SPA |
CORS_ORIGINS |
Yes | — | List of allowed browser origins |
React Companion Contract
The frontend companion react-session.manager.sk (v4.0+) uses this transport contract:
- Axios configured with
withCredentials: true,withXSRFToken: true - Cookies expected at default Flask-JWT-Extended names:
access_token_cookie(JWT)csrf_access_token(CSRF double-submit)
- CSRF header sent as
X-CSRF-TOKEN deviceUIDheader sent on every requestappVersionheader sent on every request- No
Authorizationbearer header for browser requests - Legacy
localStorage/sessionStoragebearer tokens are automatically cleared
Internal Modules
Not part of the stable API. Import at your own risk.
| Module | Content |
|---|---|
flask_session_manager_sk.cookies |
CSRF origin checks, cookie auth detection, clear_session_token_value |
flask_session_manager_sk.request |
get_agent, get_ip, get_token, get_dets_from_request |
flask_session_manager_sk.tokens |
create_token_hash, token_hint, verify_token_hash, update_token_record |
flask_session_manager_sk.extension |
SessionManager implementation details |
Migrating from Bearer Tokens
If your backend currently returns access tokens as JSON payloads (e.g.
{"access_token": "..."}) and stores them in localStorage:
- Package adoption: Wire
SessionManagerwith your user-lookup and token-refresh callbacks. - Login endpoint: Call
token_response(payload, status, access_token)instead ofjsonify(payload). This sets the HttpOnly cookie automatically. - CSRF check: Add
reject_cookie_csrf()as a@app.before_requesthook for all unsafe methods (POST, PUT, DELETE). - Frontend: Upgrade
react-session.manager.skto v4.0+. It removes bearer-token browser storage and sends cookie credentials automatically. - Backwards compatibility: Non-browser clients (API scripts, scheduled
tasks) can still send
Authorization: Bearer <token>. The CSRF check skips bearer-authenticated requests.
Development
git clone https://github.com/Skulldorom/flask-session.manager.sk.git
cd flask-session.manager.sk
# Install deps + editable package
uv sync --dev
# Run checks
uv run ruff check .
uv run ruff format --check .
uv run pytest -v
# Build
uv build
License
MIT — see LICENSE.
Release files for flask-session.manager.sk 1.0.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| flask_session_manager_sk-1.0.4.tar.gz | 26.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| flask_session_manager_sk-1.0.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 35.4 kB
Release files / flask_session_manager_sk-1.0.4.tar.gz
| Download URL | flask_session_manager_sk-1.0.4.tar.gz |
|---|---|
| Size | 26.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8f366780f9923cb984190b6650261809b8c73c3152cd00fb28f2f8e963caa148
|
|
BLAKE2b-256 checksum How to use checksums |
67ef82bf55e6221a59ebd483eee2a738bf67667a4b20262cba926024db6ff64c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 5, 2026.
Transparency logRelease files / flask_session_manager_sk-1.0.4-py3-none-any.whl
| Download URL | flask_session_manager_sk-1.0.4-py3-none-any.whl |
|---|---|
| Size | 8.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
3d29d1247e0eae00962bee0338426f0adfd88c8e613ba89e837db183d4e02d6f
|
|
BLAKE2b-256 checksum How to use checksums |
11fe5ae8a770eb32aefd0e3f9d28955121abb2667c2a4d22d456cfbfdbdcb58f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 5, 2026.
Transparency log