I'm using express session and I would like the session expiration time not to be prolonged with each client request. My demo express application setup:
const express = require('express');
const session = require('express-session')
const router = express.Router();
const app = express();
app.use(session({
secret: 'keyboard cat',
resave: false,
saveUninitialized: true,
rolling: false,
cookie: { maxAge: 100000, secure: false },
name: 'express-test',
}));
router.get('/', function(req, res, next) {
const expirationTime = req.session.cookie.expires.toISOString();
res.json( `${req.session.id} - ${expirationTime}`);
});
app.use(router);
module.exports = app;
When I open http://localhost:3000/ in my browser I see the response with sessionId and expiration time ("WqIesolw8r6PHT_QpHR4jc4R1c9noSf7 - 2020-03-25T14:01:20.984Z"), the session id is the same but the expiration time is increased on each request. This looks like rolling session behaviour, but rolling is set to false.
I'm using these versions:
"express": "~4.16.1",
"express-session": "^1.17.0",
I don't see why with having resave: false and rolling: false does express update the session expiration time.