npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2025 – Pkg Stats / Ryan Hefner

@charmander/session

v0.1.1

Published

User and guest session tokens

Downloads

6

Readme

Build status

API

Session tokens are secret strings consisting of 32 ASCII characters in the range a through p.

CSRF tokens are secret strings constisting of 30 ASCII characters in the range a through p.

Storage keys are 16-byte Buffer values that don’t need to be treated as secret.

User ids are non-null/undefined values otherwise free to be defined by the user of the SessionBox.

  • new SessionBox(storage)

  • SessionBox#get(token, callback)

    Gets a session based on a token. The session token can change after this operation, indicated by a non-null newToken property. Pass null if no token was provided.

  • SessionBox#update(session, newUserId, callback)

    Updates a session obtained from SessionBox#get with a new user id. The session token will always change after this operation, and the old session will be invalidated. Pass null to update to a guest session.

Sessions

Sessions have the following public properties:

  • newToken

    A new session token to return to the client, or null if the existing session token remains valid.

  • userId

    The user id associated with the session. null represents a guest session.

  • csrf

    The CSRF token associated with the session.

Storage

A storage implementation should provide these methods:

  • get(key, callback)

    Retrieves a user id based on a key. The callback has two parameters: error, userId.

    If the key does not exist, the retrieved value should be null (but undefined is also accepted).

  • set(key, userId, callback)

    Associates a user id with a key. The callback has one parameter: error.

    The key will not already exist.

  • delete(key, userId, callback)

    Disassociates a user id from a key. The id is provided in case the storage maintains a set of keys for each user (e.g. for the purposes of invalidating all of a user’s sessions). The callback has one parameter: error.

    If the key does not exist, no error should be produced.