Session Drivers

Session Drivers and Their Trade-offs

SESSION_DRIVER picks where the array lives; your code never changes. The cart under the default database driver, then under file, redis and cookie:

One cart, four driversShell
sudo mysql -N shop -e 'SELECT payload FROM sessions' | base64 -d | fold -w 90; echo
wc -c storage/framework/sessions/*                      # SESSION_DRIVER=file
redis-cli --scan --pattern '*cache-*'                   # SESSION_DRIVER=redis
sed 's/^#HttpOnly_//' jar | awk '!/^#/ && NF {print $6, length($7), "bytes"}'   # cookie
Output
{"_token":"NXeXEZmEpov5tfBkKTzcGaZzLM6MKFHjjNc70lFa","cart":{"items":["BK-PHP-01","BK-SQL-
01"],"count":2},"_previous":{"url":"http:\/\/127.0.0.1:8316\/cart\/add\/BK-SQL-01","route"
:null},"_flash":{"old":[],"new":[]}}
204 storage/framework/sessions/7wls1oOUDgGW8l9KE7q093aeUG1dvWgjNW5G1AOb
laravel-database-laravel-cache-dEv3E03B62s2mDR5hz8tpBNpLXBUpn8iM0jwTA7q
6VK0ciiBJb3NdLCnV4OKHar3rhhM6nG1Zy3utfZA 742 bytes
laravel-session 342 bytes
XSRF-TOKEN 342 bytes

Every driver stores the same JSON: your keys plus _token (CSRF), _previous and _flash. The table adds user_id, IP and user agent, so an account page can end a user's other sessions, at the cost of an UPDATE per request. file suits one server only. redis and memcached expire entries by TTL and serve many web servers. The cookie driver keeps nothing server-side, so it cannot block() or end a session remotely, and its cookie breaks past about 4 KB. SESSION_ENCRYPT=true encrypts the payload before any driver stores it.