# Session injection via constructor

**URL:** https://discourse.laminas.dev/t/session-injection-via-constructor/319
**Category:** Mezzio
**Tags:** expressive, session
**Created:** [October 13, 2017, 5:07am UTC](https://discourse.laminas.dev/t/session-injection-via-constructor/319 "2017-10-13T05:07:48Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![harikt](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/harikt/32/47_2.png) [@harikt](https://discourse.laminas.dev/u/harikt)
#### Post date: [October 13, 2017, 5:07am UTC](https://discourse.laminas.dev/t/session-injection-via-constructor/319/1 "2017-10-13T05:07:48Z")

</div>

Hi all,

I am not a big fan of retrieving dependencies via Request attributes. I believe dependencies should be explicit.

So the big picture :

I have pet project called [web.expressive](https://github.com/harikt/web.expressive) which tries to integrate the [dms](http://github.com/dms-org/) with zend expressive. ( I don’t think dms was developed in mind for PSR-7 requests, so its api is a bit different. )

It has an [IAuthSystem](https://github.com/dms-org/core/blob/e452f8bbffa84cbe4fbd4a7a028639e33f8d4126/src/Auth/IAuthSystem.php) system which is injected to most of the places and [controllers ( actions )](https://github.com/harikt/web.expressive/blob/2e4a5032f9ba685c760b78196cae64e59469a123/src/Http/Controllers/DmsController.php#L53) . The `AuthSystem` needs session to check if the user is logged in or not.

> <https://github.com/harikt/web.expressive/blob/2e4a5032f9ba685c760b78196cae64e59469a123/src/Auth/HktAuthSystem.php#L68>

I was trying to integrate zend-expressive-session for the `AuthSystem` . I did integrated the same via constructor injections and not making use of the Middlewares of zend-expressive-session or zend-expressive-session-ext .

I know I am doing against what expressive is doing here. But I am interested to hear your feedback about the same.

This is what it is defined in container.

> <https://github.com/harikt/web.expressive/blob/fada28b5681b829c59094898bc064715648f81bc/src/ContainerConfig.php#L94-L107>

You can see the `ServerRequestInterface` , `SessionPersistenceInterface` is injected to `LazySession` .

I have a `Session` middleware

> <https://github.com/harikt/web.expressive/blob/fada28b5681b829c59094898bc064715648f81bc/src/Http/Middleware/Session.php#L24-L33>

which is similar to the one in

> <https://github.com/zendframework/zend-expressive-session/blob/aad5e08cbe9ef2f34be40e7d7de06a8c5e1f3284/src/SessionMiddleware.php#L31-L32>

but notable one is `LazySession` is injected via constructor.

Is there any drawbacks or making use of the same ? Or is there a different approach I can follow here making use of the same Middlewares of zend-expressive-session.

I have also been looking at how @enrico is doing this on zend-expressive-authentication prototype .

> <https://github.com/ezimuel/zend-expressive-authentication/blob/42863eae5dcdca07fbfcb1975cd4eb0a9e0a101d/src/Adapter/PhpSession.php#L32-L42>

I can’t go along the way for the [core interface](https://github.com/dms-org/core/blob/e452f8bbffa84cbe4fbd4a7a028639e33f8d4126/src/Auth/IAuthSystem.php) is making use at multiple places .

The code is under session branch .

[https://github.com/harikt/web.expressive/tree/session](https://github.com/harikt/web.expressive/tree/session) ( package )

[https://github.com/harikt/dms-expressive-skeleton/tree/session](https://github.com/harikt/dms-expressive-skeleton/tree/session) ( demo )

Thank you for your valuable time.

If you have feedback I am interested to hear.

---

<div class="post-metadata">

### Author: ![ocramius](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/ocramius/32/23_2.png) [@ocramius](https://discourse.laminas.dev/u/ocramius)
#### Post date: [October 13, 2017, 5:38am UTC](https://discourse.laminas.dev/t/session-injection-via-constructor/319/2 "2017-10-13T05:38:15Z")

</div>

A session is part of the request scope (in PHP even more specifically so,  
due to share-nothing process semantics), so the initial issue (having  
session passed in at construct) is a problem on its own. It should be moved  
to call-time parameters, or you can move all parameters (including the  
request) to the constructor, and make it a request-scoped object.

That said, I don’t understand what you are asking, specifically.

Marco Pivetta

[http://twitter.com/Ocramius](http://twitter.com/Ocramius)

[http://ocramius.github.com/](http://ocramius.github.com/)

---

<div class="post-metadata">

### Author: ![harikt](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/harikt/32/47_2.png) [@harikt](https://discourse.laminas.dev/u/harikt)
#### Post date: [October 13, 2017, 6:23am UTC](https://discourse.laminas.dev/t/session-injection-via-constructor/319/3 "2017-10-13T06:23:56Z")

</div>

@ocramius So the question is why not allow users to inject `Zend\Expressive\Session\SessionInterface` into the SessionMiddleware

> <https://github.com/zendframework/zend-expressive-session/blob/aad5e08cbe9ef2f34be40e7d7de06a8c5e1f3284/src/SessionMiddlewareFactory.php#L17>

than creating an object `LazySession`

> <https://github.com/zendframework/zend-expressive-session/blob/aad5e08cbe9ef2f34be40e7d7de06a8c5e1f3284/src/SessionMiddleware.php#L31>

Which is only available via Request ?

Now the same `SessionInterface` object can be used any where via constructor injection . And the middleware can finally persist the session.

See the difference in Middleware implementations.

UPDATE : This will also be same for Flash and Csrf repos middlewares.

---

<div class="post-metadata">

### Author: ![ocramius](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/ocramius/32/23_2.png) [@ocramius](https://discourse.laminas.dev/u/ocramius)
#### Post date: [October 13, 2017, 6:37am UTC](https://discourse.laminas.dev/t/session-injection-via-constructor/319/4 "2017-10-13T06:37:53Z")

</div>

I am probably just not fully awake, but I only see  
SessionPersistenceInterface in the last two examples.

Marco Pivetta

[http://twitter.com/Ocramius](http://twitter.com/Ocramius)

[http://ocramius.github.com/](http://ocramius.github.com/)

---

<div class="post-metadata">

### Author: ![harikt](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/harikt/32/47_2.png) [@harikt](https://discourse.laminas.dev/u/harikt)
#### Post date: [October 13, 2017, 7:51am UTC](https://discourse.laminas.dev/t/session-injection-via-constructor/319/5 "2017-10-13T07:51:20Z")

</div>

I send a PR with the changes [https://github.com/zendframework/zend-expressive-session/pull/12](https://github.com/zendframework/zend-expressive-session/pull/12) . May be you now see what is different than the `SessionPersistenceInterface` .

---

<div class="post-metadata">

### Author: ![harikt](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/harikt/32/47_2.png) [@harikt](https://discourse.laminas.dev/u/harikt)
#### Post date: [October 13, 2017, 12:24pm UTC](https://discourse.laminas.dev/t/session-injection-via-constructor/319/6 "2017-10-13T12:24:18Z")

</div>

> [@ocramius](#):
>
> It should be moved to call-time parameters, or you can move all parameters (including the request) to the constructor, and make it a request-scoped object.

Can you give me an example how you are going to make use of this?

What I understand is you are saying to build the object on Middleware.

```
public function process(ServerRequestInterface $request, DelegateInterface $delegate)
{
     $auth = new HktAuthSystem($request);
}

```

If so this is not possible in the current design. There are multiple places where the IAuthSystem is injected on constructor.

---

<div class="post-metadata">

### Author: ![matthew](https://yyz2.discourse-cdn.com/flex032/user_avatar/discourse.laminas.dev/matthew/32/14_2.png) [@matthew](https://discourse.laminas.dev/u/matthew)
#### Post date: [October 16, 2017, 3:47pm UTC](https://discourse.laminas.dev/t/session-injection-via-constructor/319/7 "2017-10-16T15:47:48Z")

</div>

I’ve noted my reservations with using `SessionInterface` as a service in the [pull request you created](https://github.com/zendframework/zend-expressive-session/pull/12), and also detailed there a potential solution for your problem that does not require having the session as a service.
