diff --git a/NOTICE.md b/NOTICE.md index 23b52e94..1bf143f5 100644 --- a/NOTICE.md +++ b/NOTICE.md @@ -16,7 +16,6 @@ Shiny Server includes other open source software components. The following is a - send - connect - webkit-devtools-agent - - client-sessions - should - sinon - qs @@ -626,384 +625,6 @@ IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. ``` -### client-sessions - -``` -Mozilla Public License Version 2.0 -================================== - -1. Definitions --------------- - -1.1. "Contributor" - means each individual or legal entity that creates, contributes to - the creation of, or owns Covered Software. - -1.2. "Contributor Version" - means the combination of the Contributions of others (if any) used - by a Contributor and that particular Contributor's Contribution. - -1.3. "Contribution" - means Covered Software of a particular Contributor. - -1.4. "Covered Software" - means Source Code Form to which the initial Contributor has attached - the notice in Exhibit A, the Executable Form of such Source Code - Form, and Modifications of such Source Code Form, in each case - including portions thereof. - -1.5. "Incompatible With Secondary Licenses" - means - - (a) that the initial Contributor has attached the notice described - in Exhibit B to the Covered Software; or - - (b) that the Covered Software was made available under the terms of - version 1.1 or earlier of the License, but not also under the - terms of a Secondary License. - -1.6. "Executable Form" - means any form of the work other than Source Code Form. - -1.7. "Larger Work" - means a work that combines Covered Software with other material, in - a separate file or files, that is not Covered Software. - -1.8. "License" - means this document. - -1.9. "Licensable" - means having the right to grant, to the maximum extent possible, - whether at the time of the initial grant or subsequently, any and - all of the rights conveyed by this License. - -1.10. "Modifications" - means any of the following: - - (a) any file in Source Code Form that results from an addition to, - deletion from, or modification of the contents of Covered - Software; or - - (b) any new file in Source Code Form that contains any Covered - Software. - -1.11. "Patent Claims" of a Contributor - means any patent claim(s), including without limitation, method, - process, and apparatus claims, in any patent Licensable by such - Contributor that would be infringed, but for the grant of the - License, by the making, using, selling, offering for sale, having - made, import, or transfer of either its Contributions or its - Contributor Version. - -1.12. "Secondary License" - means either the GNU General Public License, Version 2.0, the GNU - Lesser General Public License, Version 2.1, the GNU Affero General - Public License, Version 3.0, or any later versions of those - licenses. - -1.13. "Source Code Form" - means the form of the work preferred for making modifications. - -1.14. "You" (or "Your") - means an individual or a legal entity exercising rights under this - License. For legal entities, "You" includes any entity that - controls, is controlled by, or is under common control with You. For - purposes of this definition, "control" means (a) the power, direct - or indirect, to cause the direction or management of such entity, - whether by contract or otherwise, or (b) ownership of more than - fifty percent (50%) of the outstanding shares or beneficial - ownership of such entity. - -2. License Grants and Conditions --------------------------------- - -2.1. Grants - -Each Contributor hereby grants You a world-wide, royalty-free, -non-exclusive license: - -(a) under intellectual property rights (other than patent or trademark) - Licensable by such Contributor to use, reproduce, make available, - modify, display, perform, distribute, and otherwise exploit its - Contributions, either on an unmodified basis, with Modifications, or - as part of a Larger Work; and - -(b) under Patent Claims of such Contributor to make, use, sell, offer - for sale, have made, import, and otherwise transfer either its - Contributions or its Contributor Version. - -2.2. Effective Date - -The licenses granted in Section 2.1 with respect to any Contribution -become effective for each Contribution on the date the Contributor first -distributes such Contribution. - -2.3. Limitations on Grant Scope - -The licenses granted in this Section 2 are the only rights granted under -this License. No additional rights or licenses will be implied from the -distribution or licensing of Covered Software under this License. -Notwithstanding Section 2.1(b) above, no patent license is granted by a -Contributor: - -(a) for any code that a Contributor has removed from Covered Software; - or - -(b) for infringements caused by: (i) Your and any other third party's - modifications of Covered Software, or (ii) the combination of its - Contributions with other software (except as part of its Contributor - Version); or - -(c) under Patent Claims infringed by Covered Software in the absence of - its Contributions. - -This License does not grant any rights in the trademarks, service marks, -or logos of any Contributor (except as may be necessary to comply with -the notice requirements in Section 3.4). - -2.4. Subsequent Licenses - -No Contributor makes additional grants as a result of Your choice to -distribute the Covered Software under a subsequent version of this -License (see Section 10.2) or under the terms of a Secondary License (if -permitted under the terms of Section 3.3). - -2.5. Representation - -Each Contributor represents that the Contributor believes its -Contributions are its original creation(s) or it has sufficient rights -to grant the rights to its Contributions conveyed by this License. - -2.6. Fair Use - -This License is not intended to limit any rights You have under -applicable copyright doctrines of fair use, fair dealing, or other -equivalents. - -2.7. Conditions - -Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted -in Section 2.1. - -3. Responsibilities -------------------- - -3.1. Distribution of Source Form - -All distribution of Covered Software in Source Code Form, including any -Modifications that You create or to which You contribute, must be under -the terms of this License. You must inform recipients that the Source -Code Form of the Covered Software is governed by the terms of this -License, and how they can obtain a copy of this License. You may not -attempt to alter or restrict the recipients' rights in the Source Code -Form. - -3.2. Distribution of Executable Form - -If You distribute Covered Software in Executable Form then: - -(a) such Covered Software must also be made available in Source Code - Form, as described in Section 3.1, and You must inform recipients of - the Executable Form how they can obtain a copy of such Source Code - Form by reasonable means in a timely manner, at a charge no more - than the cost of distribution to the recipient; and - -(b) You may distribute such Executable Form under the terms of this - License, or sublicense it under different terms, provided that the - license for the Executable Form does not attempt to limit or alter - the recipients' rights in the Source Code Form under this License. - -3.3. Distribution of a Larger Work - -You may create and distribute a Larger Work under terms of Your choice, -provided that You also comply with the requirements of this License for -the Covered Software. If the Larger Work is a combination of Covered -Software with a work governed by one or more Secondary Licenses, and the -Covered Software is not Incompatible With Secondary Licenses, this -License permits You to additionally distribute such Covered Software -under the terms of such Secondary License(s), so that the recipient of -the Larger Work may, at their option, further distribute the Covered -Software under the terms of either this License or such Secondary -License(s). - -3.4. Notices - -You may not remove or alter the substance of any license notices -(including copyright notices, patent notices, disclaimers of warranty, -or limitations of liability) contained within the Source Code Form of -the Covered Software, except that You may alter any license notices to -the extent required to remedy known factual inaccuracies. - -3.5. Application of Additional Terms - -You may choose to offer, and to charge a fee for, warranty, support, -indemnity or liability obligations to one or more recipients of Covered -Software. However, You may do so only on Your own behalf, and not on -behalf of any Contributor. You must make it absolutely clear that any -such warranty, support, indemnity, or liability obligation is offered by -You alone, and You hereby agree to indemnify every Contributor for any -liability incurred by such Contributor as a result of warranty, support, -indemnity or liability terms You offer. You may include additional -disclaimers of warranty and limitations of liability specific to any -jurisdiction. - -4. Inability to Comply Due to Statute or Regulation ---------------------------------------------------- - -If it is impossible for You to comply with any of the terms of this -License with respect to some or all of the Covered Software due to -statute, judicial order, or regulation then You must: (a) comply with -the terms of this License to the maximum extent possible; and (b) -describe the limitations and the code they affect. Such description must -be placed in a text file included with all distributions of the Covered -Software under this License. Except to the extent prohibited by statute -or regulation, such description must be sufficiently detailed for a -recipient of ordinary skill to be able to understand it. - -5. Termination --------------- - -5.1. The rights granted under this License will terminate automatically -if You fail to comply with any of its terms. However, if You become -compliant, then the rights granted under this License from a particular -Contributor are reinstated (a) provisionally, unless and until such -Contributor explicitly and finally terminates Your grants, and (b) on an -ongoing basis, if such Contributor fails to notify You of the -non-compliance by some reasonable means prior to 60 days after You have -come back into compliance. Moreover, Your grants from a particular -Contributor are reinstated on an ongoing basis if such Contributor -notifies You of the non-compliance by some reasonable means, this is the -first time You have received notice of non-compliance with this License -from such Contributor, and You become compliant prior to 30 days after -Your receipt of the notice. - -5.2. If You initiate litigation against any entity by asserting a patent -infringement claim (excluding declaratory judgment actions, -counter-claims, and cross-claims) alleging that a Contributor Version -directly or indirectly infringes any patent, then the rights granted to -You by any and all Contributors for the Covered Software under Section -2.1 of this License shall terminate. - -5.3. In the event of termination under Sections 5.1 or 5.2 above, all -end user license agreements (excluding distributors and resellers) which -have been validly granted by You or Your distributors under this License -prior to termination shall survive termination. - -************************************************************************ -* * -* 6. Disclaimer of Warranty * -* ------------------------- * -* * -* Covered Software is provided under this License on an "as is" * -* basis, without warranty of any kind, either expressed, implied, or * -* statutory, including, without limitation, warranties that the * -* Covered Software is free of defects, merchantable, fit for a * -* particular purpose or non-infringing. The entire risk as to the * -* quality and performance of the Covered Software is with You. * -* Should any Covered Software prove defective in any respect, You * -* (not any Contributor) assume the cost of any necessary servicing, * -* repair, or correction. This disclaimer of warranty constitutes an * -* essential part of this License. No use of any Covered Software is * -* authorized under this License except under this disclaimer. * -* * -************************************************************************ - -************************************************************************ -* * -* 7. Limitation of Liability * -* -------------------------- * -* * -* Under no circumstances and under no legal theory, whether tort * -* (including negligence), contract, or otherwise, shall any * -* Contributor, or anyone who distributes Covered Software as * -* permitted above, be liable to You for any direct, indirect, * -* special, incidental, or consequential damages of any character * -* including, without limitation, damages for lost profits, loss of * -* goodwill, work stoppage, computer failure or malfunction, or any * -* and all other commercial damages or losses, even if such party * -* shall have been informed of the possibility of such damages. This * -* limitation of liability shall not apply to liability for death or * -* personal injury resulting from such party's negligence to the * -* extent applicable law prohibits such limitation. Some * -* jurisdictions do not allow the exclusion or limitation of * -* incidental or consequential damages, so this exclusion and * -* limitation may not apply to You. * -* * -************************************************************************ - -8. Litigation -------------- - -Any litigation relating to this License may be brought only in the -courts of a jurisdiction where the defendant maintains its principal -place of business and such litigation shall be governed by laws of that -jurisdiction, without reference to its conflict-of-law provisions. -Nothing in this Section shall prevent a party's ability to bring -cross-claims or counter-claims. - -9. Miscellaneous ----------------- - -This License represents the complete agreement concerning the subject -matter hereof. If any provision of this License is held to be -unenforceable, such provision shall be reformed only to the extent -necessary to make it enforceable. Any law or regulation which provides -that the language of a contract shall be construed against the drafter -shall not be used to construe this License against a Contributor. - -10. Versions of the License ---------------------------- - -10.1. New Versions - -Mozilla Foundation is the license steward. Except as provided in Section -10.3, no one other than the license steward has the right to modify or -publish new versions of this License. Each version will be given a -distinguishing version number. - -10.2. Effect of New Versions - -You may distribute the Covered Software under the terms of the version -of the License under which You originally received the Covered Software, -or under the terms of any subsequent version published by the license -steward. - -10.3. Modified Versions - -If you create software not governed by this License, and you want to -create a new license for such software, you may create and use a -modified version of this License if you rename the license and remove -any references to the name of the license steward (except to note that -such modified license differs from this License). - -10.4. Distributing Source Code Form that is Incompatible With Secondary -Licenses - -If You choose to distribute Source Code Form that is Incompatible With -Secondary Licenses under the terms of this version of the License, the -notice described in Exhibit B of this License must be attached. - -Exhibit A - Source Code Form License Notice -------------------------------------------- - - This Source Code Form is subject to the terms of the Mozilla Public - License, v. 2.0. If a copy of the MPL was not distributed with this - file, You can obtain one at http://mozilla.org/MPL/2.0/. - -If it is not possible or desirable to put the notice in a particular -file, then You may include the notice in a location (such as a LICENSE -file in a relevant directory) where a recipient would be likely to look -for such a notice. - -You may add additional accurate notices of copyright ownership. - -Exhibit B - "Incompatible With Secondary Licenses" Notice ---------------------------------------------------------- - - This Source Code Form is "Incompatible With Secondary Licenses", as - defined by the Mozilla Public License, v. 2.0. -``` - ### should ``` diff --git a/lib/server-init.js b/lib/server-init.js index 4b4d71c5..94084ea5 100644 --- a/lib/server-init.js +++ b/lib/server-init.js @@ -25,11 +25,9 @@ // app.handle mutates req.url before morgan reads req.originalUrl. require('./core/log'); -var crypto = require('crypto'); var fs = require('fs'); var url = require('url'); var compression = require('compression'); -var client_sessions = require('client-sessions'); var express = require('express'); var morgan = require('morgan'); var Q = require('q'); @@ -109,10 +107,6 @@ function createServer_p(configFilePath, options) { var compressionMiddleware = compression(); let useCompression = true; - var clientSessionMiddleware = client_sessions({ - secret: crypto.randomBytes(16).toString('hex') - }); - // Setup a placeholder middleware function until we can create one after // parsing the config. var sockjsServer = false; @@ -132,7 +126,6 @@ function createServer_p(configFilePath, options) { else next(); }); - app.use(clientSessionMiddleware); app.use(function(req, res, next) { if (!sockjsHandler(req, res)) next(); @@ -202,13 +195,7 @@ function createServer_p(configFilePath, options) { res.end(); return; } - // KNOWN DEFECT (characterized, not yet fixed): passing null for `res` - // makes client-sessions throw internally and call back on nextTick with an - // error this callback ignores, so req.session is never defined on the - // upgrade path. See memory-bank/requestLifecycle.md §7. - clientSessionMiddleware(request, null, function() { - sockjsHandler.upgrade(request, socket, head); - }); + sockjsHandler.upgrade(request, socket, head); }); var requestLogger = null; diff --git a/memory-bank/proxyLayer.md b/memory-bank/proxyLayer.md index d9b681b6..e1ea009f 100644 --- a/memory-bank/proxyLayer.md +++ b/memory-bank/proxyLayer.md @@ -132,7 +132,6 @@ What actually crosses the proxy boundary, verified rather than assumed: | `connection: close` | to worker | forced by http-proxy (agent=false) | | `x-frame-options` | to browser | `lib/proxy/http.js:257`, from `appDefaults.frameOptions` | | `X-Powered-By: ` | to browser | `lib/server-init.js` (express's own is disabled) | -| `session_state` cookie | to browser | `client-sessions` middleware, `lib/server-init.js,170` | **There are no `X-Forwarded-*` headers.** `http-proxy` only adds them when `options.xfwd` is set (`passes/web-incoming.js:72`), and Shiny Server never sets it. @@ -146,14 +145,24 @@ spawned it. There is no `Shiny-Server-*` header — the equivalent information to the worker once at spawn time as JSON on stdin (`lib/worker/app-worker.ts:560-592`), and the R side injects it into the page for `shiny-server-client` to read. -**Surprise:** the `client-sessions` middleware is applied to upgrade requests as -`clientSessionMiddleware(request, null, cb)` (`lib/server-init.js`). With `res === null` -the `Session` constructor throws on `res.socket` -(`node_modules/client-sessions/lib/client-sessions.js:378`), the library catches it and -calls `next(err)` on `process.nextTick`, and `lib/main.js` ignores the error argument. -Verified empirically. So WebSocket upgrades work, but only by accident, and one tick -later than they look. Also, nothing in `lib/` ever *reads* `req.session_state`; the -middleware appears vestigial. +**Sets no cookies at all.** Shiny Server's own middleware stack never calls +`res.setHeader('set-cookie', ...)`, and there is no session middleware left (see +below). Client cookies are forwarded to the worker verbatim, but nothing is minted +here. Verified against a live `/r-hello/` response. + +**Removed: `client-sessions`.** Until 2026-09 a `client-sessions` middleware sat in +the stack and was also applied to upgrade requests as +`clientSessionMiddleware(request, null, cb)`. It was fully vestigial and has been +deleted: nothing in `lib/`, `test/`, `R/`, or `assets/` ever read `req.session_state`, +and because the lazy `Session.content` getter was never touched the session stayed +`loaded === false` / `dirty === false`, so `updateCookie()` was a no-op and *no +`session_state` cookie was ever emitted* (verified empirically). On the upgrade path +`res === null` made the `Session` constructor throw on `res.socket`; the library caught +it and called `next(err)` on `process.nextTick`, and the callback ignored the argument +— so upgrades worked, one tick late, with no session. It was added in `280b075` +(Apr 2013) as infrastructure for Shiny Server Pro's auth layer, which never shipped in +open source. The upgrade handler now calls `sockjsHandler.upgrade()` directly. Do not +reintroduce it looking for a session cookie that never existed. ## Connection accounting (get this right) diff --git a/memory-bank/requestLifecycle.md b/memory-bank/requestLifecycle.md index 4f4827ad..b85d0f6f 100644 --- a/memory-bank/requestLifecycle.md +++ b/memory-bank/requestLifecycle.md @@ -81,7 +81,7 @@ sockjsServer = proxy_sockjs.createServer(metarouter, schedulerRegistry, ...) (R Server (facade) ──> N x http.Server, one per unique listen address 'request' -> app.handle (express) AND -> requestLogger (morgan) - 'upgrade' -> clientSessionMiddleware -> sockjsHandler.upgrade + 'upgrade' -> sockjsHandler.upgrade ``` Two seams make reload possible without rebuilding the world: @@ -127,10 +127,14 @@ Installed in this exact order (`lib/server-init.js`): |---|---|---| | 1 | `X-Powered-By: Shiny Server` | Express's own header is disabled at `:159` first. | | 2 | conditional `compression()` | Guarded by the mutable `useCompression` flag, so `http_allow_compression` is honored per-request after a reload. | -| 3 | `client-sessions` | Random per-process secret (`lib/server-init.js`). | -| 4 | `sockjsHandler` | `if (!sockjsHandler(req,res)) next()`. | -| 5 | `__assets__` filter | `connect_util.filterByRegex(/\b__assets__\/.+/, ...)`. | -| 6 | `shinyProxy.httpListener` | Terminal — never calls `next()`. | +| 3 | `sockjsHandler` | `if (!sockjsHandler(req,res)) next()`. | +| 4 | `__assets__` filter | `connect_util.filterByRegex(/\b__assets__\/.+/, ...)`. | +| 5 | `shinyProxy.httpListener` | Terminal — never calls `next()`. | + +There is **no session middleware**. A `client-sessions` entry sat at position 3 until +2026-09; it was entirely vestigial and was removed. See +`memory-bank/proxyLayer.md` for the full autopsy — in particular, it never emitted a +cookie, so don't go looking for one. Why the order matters: @@ -142,9 +146,6 @@ Why the order matters: middlewares must therefore run before the proxy, and the assets regex is deliberately unanchored (`\b__assets__\/`) with everything up to and including `__assets__/` stripped from `req.url` at `lib/server-init.js`. -- **`client-sessions` before SockJS.** The session cookie is established before - SockJS transport requests are handled. (In practice nothing in `lib/` ever - reads `req.session`; the middleware looks vestigial.) - **The proxy is terminal.** `httpListener(req, res)` takes no `next`. Every path through it either responds (404/500/503) or hands off to `http-proxy`. There is no error-handling middleware anywhere in the app, so Express's @@ -211,15 +212,15 @@ Shiny Server ⇄ worker (a plain WebSocket via `faye-websocket`). **HTTP-based SockJS transports** (xhr-polling, xhr-streaming, jsonp, eventsource, htmlfile, plus `/info` and the iframe/welcome pages) arrive as ordinary requests -and are claimed by middleware #4. The SockJS prefix is +and are claimed by middleware #3. The SockJS prefix is `'.*/__sockjs__(/[no]=\\w+)?'` (`lib/proxy/sockjs.js:42`) — the leading `.*` is what lets a single SockJS server serve every app prefix, and the optional `/n=` / `/o=` path param is the robust-reconnect session id consumed by `lib/proxy/robust-sockjs.js`. **WebSocket upgrades** bypass Express entirely — Express only handles -`'request'`. `lib/server-init.js` handles `'upgrade'` on the `Server` facade, -manually running `clientSessionMiddleware` and then `sockjsHandler.upgrade`. +`'request'`. `lib/server-init.js` handles `'upgrade'` on the `Server` facade by +calling `sockjsHandler.upgrade` directly. Once SockJS produces a connection (`lib/proxy/sockjs.js:49-62`) it goes through two wrappers before routing: @@ -300,7 +301,7 @@ logger; `socketTimeout`; `useCompression`; the set of bound listeners. Preserved: the event bus; the entire router decorator chain and `LocalConfigRouter`'s `AppConfig` cache; the `SchedulerRegistry` **and every running worker process**; the transport; the Express app and its middleware -instances; the `client-sessions` secret; and any `http.Server` whose +instances; and any `http.Server` whose address/port is unchanged (`Server.setAddresses` diffs by `http://:` key and only opens/closes the delta, `lib/server/server.js`). Existing connections on a *removed* listener are @@ -355,12 +356,11 @@ the `128+signal` convention. (`lib/server-init.js`, marked `KNOWN DEFECT` in place) — a `ReferenceError` if an upgrade arrives before the config finishes loading. Characterized but deliberately not fixed yet. -- **`clientSessionMiddleware(request, null, cb)`** on the upgrade path - (`lib/server-init.js`, also marked `KNOWN DEFECT`) passes `null` for `res`. `client-sessions` dereferences - `res.socket`, throws inside its `try`, and calls `next(err)` on `nextTick`. - The callback ignores its argument, so upgrades still work — one tick later, - with no `req.session` defined. Verified against - `node_modules/client-sessions/lib/client-sessions.js:355-383,600-630`. +- **FIXED (2026-09): the `client-sessions`-on-upgrade swallow.** The middleware + was removed outright rather than repaired, because it was vestigial; the + upgrade handler now calls `sockjsHandler.upgrade()` directly and synchronously. + See `memory-bank/proxyLayer.md`. The pre-config `res` defect above is + unrelated and still open. - **`server.listening` is read-only.** `lib/server/server.js` used to assign `server.listening = true/false`; that was a silent no-op, because `net.Server.prototype.listening` is a getter with no setter, so in sloppy mode diff --git a/memory-bank/techContext.md b/memory-bank/techContext.md index 192da6fb..140b4d9e 100644 --- a/memory-bank/techContext.md +++ b/memory-bank/techContext.md @@ -28,7 +28,7 @@ From `package.json` `dependencies`: | Role | Packages | | --- | --- | -| HTTP framework / middleware | `express` (v5), `compression`, `morgan`, `client-sessions`, `send`, `mime-types`, `qs`, `pause` | +| HTTP framework / middleware | `express` (v5), `compression`, `morgan`, `send`, `mime-types`, `qs`, `pause` | | Proxying | `http-proxy-3` | | WebSocket / SockJS | `faye-websocket`, `sockjs` (server), `sockjs-client` (served to browsers), `shiny-server-client` | | CLI / config | `optimist` (argv parsing), `ip-address` (config validation) | diff --git a/npm-shrinkwrap.json b/npm-shrinkwrap.json index 3cfae224..95912907 100644 --- a/npm-shrinkwrap.json +++ b/npm-shrinkwrap.json @@ -10,7 +10,6 @@ "license": "AGPL-3.0", "dependencies": { "bash": "0.0.1", - "client-sessions": "^0.8.0", "compression": "^1.8.1", "express": "^5.2.1", "faye-websocket": "^0.11.4", @@ -49,7 +48,7 @@ "typescript": "^7.0.2" }, "engines": { - "node": ">=18.0.0", + "node": ">=22.0.0", "npm": ">=7.0.0" } }, @@ -1145,17 +1144,6 @@ "fsevents": "~2.3.2" } }, - "node_modules/client-sessions": { - "version": "0.8.0", - "resolved": "https://registry.npmjs.org/client-sessions/-/client-sessions-0.8.0.tgz", - "integrity": "sha512-XERL6B5cJYGEaAigTADRr8NrUhkGmIUdrlHBzRM62uZEtFben5QYbaOxgWX79wFbCIvABhgZCWch1glw2fcyiQ==", - "dependencies": { - "cookies": "^0.7.0" - }, - "engines": { - "node": ">= 0.8.0" - } - }, "node_modules/cliui": { "version": "8.0.1", "resolved": "https://registry.npmjs.org/cliui/-/cliui-8.0.1.tgz", @@ -1348,18 +1336,6 @@ "node": ">=6.6.0" } }, - "node_modules/cookies": { - "version": "0.7.3", - "resolved": "https://registry.npmjs.org/cookies/-/cookies-0.7.3.tgz", - "integrity": "sha512-+gixgxYSgQLTaTIilDHAdlNPZDENDQernEMiIcZpYYP14zgHsCt4Ce1FEjFtcp6GefhozebB6orvhAAWx/IS0A==", - "dependencies": { - "depd": "~1.1.2", - "keygrip": "~1.0.3" - }, - "engines": { - "node": ">= 0.8" - } - }, "node_modules/cross-spawn": { "version": "7.0.6", "resolved": "https://registry.npmjs.org/cross-spawn/-/cross-spawn-7.0.6.tgz", @@ -1410,14 +1386,6 @@ "dev": true, "license": "MIT" }, - "node_modules/depd": { - "version": "1.1.2", - "resolved": "https://registry.npmjs.org/depd/-/depd-1.1.2.tgz", - "integrity": "sha512-7emPTl6Dpo6JRXOXjLRxck+FlLRX5847cLKEn00PLAgc3g2hTZZgr+e4c2v6QpSmLeFP3n5yUo7ft6avBK/5jQ==", - "engines": { - "node": ">= 0.6" - } - }, "node_modules/diff": { "version": "9.0.0", "resolved": "https://registry.npmjs.org/diff/-/diff-9.0.0.tgz", @@ -2608,14 +2576,6 @@ "graceful-fs": "^4.1.6" } }, - "node_modules/keygrip": { - "version": "1.0.3", - "resolved": "https://registry.npmjs.org/keygrip/-/keygrip-1.0.3.tgz", - "integrity": "sha512-/PpesirAIfaklxUzp4Yb7xBper9MwP6hNRA6BGGUFCgbJ+BM5CKBtsoxinNXkLHAr+GXS1/lSlF2rP7cv5Fl+g==", - "engines": { - "node": ">= 0.6" - } - }, "node_modules/keyv": { "version": "4.5.4", "resolved": "https://registry.npmjs.org/keyv/-/keyv-4.5.4.tgz", diff --git a/package.json b/package.json index 8454b9c0..f0a55f09 100644 --- a/package.json +++ b/package.json @@ -20,7 +20,6 @@ }, "dependencies": { "bash": "0.0.1", - "client-sessions": "^0.8.0", "compression": "^1.8.1", "express": "^5.2.1", "faye-websocket": "^0.11.4",