createCookieSessionStorage session expiration with conflicting maxAge and expires
0 reputation · 06 Apr 2024, 04:28 UTC
When configuring session storage in Remix using createCookieSessionStorage, the API allows for the definition of both maxAge (defined in seconds) and expires (defined as a Date object) to control cookie lifetime.
There is uncertainty regarding the precedence logic when both properties are provided simultaneously. Specifically, it is unclear if the framework prioritizes the relative duration of maxAge or the absolute timestamp of expires when generating the Set-Cookie header.
This ambiguity complicates the implementation of precise session timeouts, as browser-level interpretation of these overlapping attributes can vary.
- Which property takes precedence when both
maxAgeandexpiresare defined? - Does the framework calculate a combined expiration, or does one explicitly override the other?