{"id":14975681,"url":"https://github.com/kyleross/goose-session","last_synced_at":"2026-03-04T02:03:09.734Z","repository":{"id":57252479,"uuid":"41432376","full_name":"KyleRoss/goose-session","owner":"KyleRoss","description":"A lightweight Express 4.x Session Store using the Mongoose ODM","archived":false,"fork":false,"pushed_at":"2018-02-13T17:04:00.000Z","size":9,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-10-25T20:55:08.498Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/KyleRoss.png","metadata":{"files":{"readme":"README.md","changelog":"HISTORY.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2015-08-26T15:06:20.000Z","updated_at":"2016-12-05T20:07:21.000Z","dependencies_parsed_at":"2022-08-31T22:20:50.597Z","dependency_job_id":null,"html_url":"https://github.com/KyleRoss/goose-session","commit_stats":null,"previous_names":[],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/KyleRoss/goose-session","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KyleRoss%2Fgoose-session","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KyleRoss%2Fgoose-session/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KyleRoss%2Fgoose-session/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KyleRoss%2Fgoose-session/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/KyleRoss","download_url":"https://codeload.github.com/KyleRoss/goose-session/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KyleRoss%2Fgoose-session/sbom","scorecard":{"id":81114,"data":{"date":"2025-08-11","repo":{"name":"github.com/KyleRoss/goose-session","commit":"32bdb7c83cc89875c6ef3a5debba18ad693d1c4c"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.2,"checks":[{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Code-Review","score":1,"reason":"Found 1/6 approved changesets -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 2 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-15T05:53:48.527Z","repository_id":57252479,"created_at":"2025-08-15T05:53:48.527Z","updated_at":"2025-08-15T05:53:48.527Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":285889733,"owners_count":27248884,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-11-23T02:00:06.149Z","response_time":135,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-09-24T13:52:23.062Z","updated_at":"2025-11-23T02:01:53.242Z","avatar_url":"https://github.com/KyleRoss.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# goose-session\n[![npm](https://img.shields.io/npm/v/goose-session.svg?style=flat-square)](https://www.npmjs.com/package/goose-session) [![GitHub issues](https://img.shields.io/github/issues/KyleRoss/goose-session.svg?style=flat-square)](https://github.com/KyleRoss/goose-session/issues) [![npm](https://img.shields.io/npm/dm/goose-session.svg?style=flat-square)](https://www.npmjs.com/package/goose-session) [![GitHub license](https://img.shields.io/badge/license-MIT-blue.svg?style=flat-square)](https://raw.githubusercontent.com/KyleRoss/goose-session/master/LICENSE)\n\nA lightweight [Express 3.x / 4.x](http://expressjs.com/) Session Store using an established connection through [Mongoose ODM](http://mongoosejs.com/). This session store takes a pre-existing connection using Mongoose and uses that for the session store instead of opening a new connection. It provides an easy way to store sessions in MongoDB without flooding connections along with allowing full configuration over your connection and error handling.\n\n_Why reconnect to the same database twice?_\n\n**goose-session vs. the others**\n\n| Feature                                                      | goose-session      | the others\n| ------------------------------------------------------------ | ------------------ | ------------\n| Use your pre-existing Mongoose connection                    | :white_check_mark: | :x:\n| Use your own Mongoose connection error handling/reconnection | :white_check_mark: | :x: (some have config properties)\n| Provide full Mongoose configuration for the connection       | :white_check_mark: | :x:\n| Switch between Mongo replica sets and single connections     | :white_check_mark: | :x: (usually requires separate modules)\n| Full control over Mongoose Schema and Model                  | :white_check_mark: | :x:\n| Express 3.x and 4.x support                                  | :white_check_mark: | :white_check_mark: (depends on module)\n| Requires Mongoose as a dependency                            | :x:                | :white_check_mark:\n| Handles connecting to different servers/databases*           | :x:                | :white_check_mark:\n\n\u003csmall\u003e\u003cem\u003e* - Since goose-session uses your mongoose connection to store sessions, you cannot disconnect and connect to other databases/servers otherwise all initialized sessions will no longer exist in the new database. If you are connecting to different servers/databases within your app, you would either need to create a new separate mongoose connection instance or use one of the alternative modules out there that creates it's own connection.\u003c/em\u003e\u003c/small\u003e\n\n## Install\nInstall via npm:\n\n    npm install goose-session --save\n\nYou should have already installed the following dependencies to your application:\n\n    npm install express express-session cookie-parser --save\n\n\n## Full Example\n\n    var express = require('express'),\n        session = require('express-session'),\n        cookieParser = require('cookie-parser'),\n        gooseSession = require('goose-session'),\n        mongoose = require('mongoose'),\n        app = express();\n    \n    // Set an error handler\n    mongoose.connection.on('error', function(err) {\n        console.error('MongoDB Error:', err);\n    });\n    \n    // Connect to Mongo\n    mongoose.connect('mongodb://localhost:27017/app', {\n        user: 'mongoUser',\n        pass: 'mongoPass',\n        server: {\n            // Good idea to keep the connection alive\n            socketOptions: { keepAlive: 1 }\n        }\n    });\n    \n    // Add cookie parser middleware (needed for sessions)\n    app.use(cookieParser());\n    \n    // Add express-session middleware\n    app.use(session({\n        // Tell express-session to use goose-session as the store\n        store: gooseSession(mongoose, {\n            // goose-session options...\n            collection: 'sessions',\n            expireAfter: '3d'\n        }),\n        \n        // express-session configuration\n        secret: 'mySecretKey',\n        name: 'app.session',\n        rolling: true,\n        saveUninitialized: false,\n        unset: 'destroy'\n    }));\n    \n    // Start the server\n    app.listen(3000, function() {\n        console.log('Server listening on port 3000');\n    });\n    \n    \nThis example shows a very basic express application with a MongoDB connection. We start out by creating an error event handler for Mongoose to handle errors when they happen. You would typically have other event handlers also like `disconnected` and `open`, it just all depends on what you need for your application. Remember that this MongoDB connection is for your app too, not just the sessions, so you should have whatever you need for your application; there is nothing special needed for goose-session.\n\nAfter creating the connection using `mongoose.connect(...)`, we will add a piece of Express middleware that uses [express-session](https://github.com/expressjs/session). Inside the configuration for express-session, we tell it to use `gooseSession` as the store (or storage system) for the sessions. We provide the `mongoose` instance as the first argument and an optional options object as the second _(available options are listed below)_. After `store`, we also provide some additional configuration options to express-session which is outlined in their [documentation](https://github.com/expressjs/session). These options are not required for goose-session, but there are a couple that is required by express-session. It's also a good idea to set the following express-session options:\n\n* `rolling: true` - Forces the cookie to be set by the browser on every response in order for the expiration date to be updated.\n* `saveUninitialized: false` - If your sessions are authentication-based, you can set this property to false to prevent \"empty\" sessions from being saved to the store.\n* `unset: 'destroy'` - Tells express-session that when the session is nulled or deleted, it should also be removed from the store.\n\nLastly, we start the express server on port `3000`.\n\n## Usage\nRequire `goose-session` and `express-session`:\n\n    var gooseSession = require('goose-session'),\n        session = require('express-session');\n\nAdd express-session middleware with the `store` set to goose-session:\n\n    app.use(session({\n        store: gooseSession(mongoose, { ... }),\n        ...\n    }));\n\n---\n\n### GooseSession(mongoose[, options])\nThe goose-session constructor that provides all the required methods to express-session for storing sessions.\n\n*Arguments*\n\n| Required? | Argument | Type         | Description\n| --------- | -------- | ------------ | ------------------------------------------\n| Yes       | mongoose | _Mongoose()_ | The mongoose instance `require('mongoose')`.\n| No        | options  | Object       | Optional configuration for goose-session. See _options_ below.\n\n---\n\n### Options\nThe following configuration options are available:\n\n#### schema\n_Object | Mongoose.Schema_\u003cbr\u003e\nThe schema to use for the session. You can either pass an object in the format that Mongoose.Schema uses or a created Mongoose.Schema object.\n\nDefault:\n\n    new mongoose.Schema({\n        session: mongoose.Schema.Types.Mixed,\n        expires: { type: Date, expires: this.options.expireAfter }\n    });\n\nNOTE: If you are using your own schema and use a different key name than `session`, you need to set `options.sessionKey` also.\n\n#### model\n_Mongoose.model_\u003cbr\u003e\nA custom model that has already been initialized. If `model` is provided, then `schema` is ignored.\n\nDefault:\n\n    mongoose.model(this.options.collection, sessionSchema);\n\n#### collection\n_String_\u003cbr\u003e\nThe name of the collection to store sessions in. Ignored if `model` is provided. Default is `sessions`.\n\n#### expireAfter\n_Number | String_\u003cbr\u003e\nThe time in milliseconds (number) or string formatted using the [ms module](https://www.npmjs.com/package/ms) that the session should expire when there is no activity. Default is `6h` (6 hours).\n\n#### sessionKey\n_String_\u003cbr\u003e\nThe name of the key that stores session information inside the `schema`. Only needed if you are using your own schema with a different key to store session information. Default is `session`.\n\n## Issues\nFound a bug? Have an enhancement? Create a new issue. I will try to get it fixed as soon as possible.\n\n## Contributing\nWant to contribute to the project? Fork and submit a pull request.\n\n## License\nLicensed under the MIT license. See LICENSE in the repository for more information.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkyleross%2Fgoose-session","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkyleross%2Fgoose-session","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkyleross%2Fgoose-session/lists"}