# Session data in phpunittest

**URL:** <https://discourse.cakephp.org/t/session-data-in-phpunittest/12214>\
**Category:** Testing\
**Tags:** behavior, help\
**Created:** [August 30, 2024, 8:18pm UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214 "2024-08-30T20:18:17Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![webdeveloper](https://avatars.discourse-cdn.com/v4/letter/w/c4cdca/32.png) [@webdeveloper](https://discourse.cakephp.org/u/webdeveloper)\
**Post date:** [August 30, 2024, 8:18pm UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214/1 "2024-08-30T20:18:17Z")

</div>

In my test controller, in a test action, I am setting the Auth.User session.

```auto
$this->session(['Auth' => ['User' => $user->toArray()]]);

```

But in my Behavior I am not able to get the session data. When I print `$_SESSION['Auth']`, I get nothing.

I am on CakePHP 4.4 and PHP Unit 9.6

---

<div class="post-metadata">

**Author:** ![jmcd73](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/jmcd73/32/481_2.png) [@jmcd73](https://discourse.cakephp.org/u/jmcd73)\
**Post date:** [August 30, 2024, 10:49pm UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214/2 "2024-08-30T22:49:03Z")

</div>

This is where I resort to `dd()` so I can see what is going on

In methods in your behavior which will be called when you are making your request try:

```php
  dd($_SESSION);
  dd(Router::getRequest()->getSession()->read('Auth'));

```

In your test method you can see the output of the response or just dump $\_SESSION

```php
// controller test class
public function testTimeStampBehavior()
    {
        $this->session(['Auth' => ['id' => 1]]);
        $this->enableCsrfToken();
        $this->post('/users/add', ['username' => 'james', 'password' => 'abc']);
        // dd($this->_response->getBody()->__toString());
        dd($_SESSION);
        $this->assertResponseCode(302);
        $this->assertSessionHasKey('Auth.id');
    }

```

Output

```php
########## DEBUG ##########
[
  'Auth' => [
    'id' => (int) 1
  ],
  'csrfToken' => 'naGNd/Oa6I0nxTexK5Jn6jE2ZmJkNjI4M2ZmM2ZmOTJhZjQyNTFkNDExOTRlNWJmYWEwNTEzN2Q=',
  'Flash' => [
    'flash' => [
      (int) 0 => [
        'message' => 'The user has been saved.',
        'key' => 'flash',
        'element' => 'flash/success',
        'params' => []
      ]
    ]
  ]
]
###########################

```

---

<div class="post-metadata">

**Author:** ![jmcd73](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/jmcd73/32/481_2.png) [@jmcd73](https://discourse.cakephp.org/u/jmcd73)\
**Post date:** [August 31, 2024, 4:59am UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214/3 "2024-08-31T04:59:25Z")

</div>

On another note the documentation says `Auth.User.id` but I’m not seeing that in practice

 ![image](https://canada1.discourse-cdn.com/flex029/uploads/cakephp/original/2X/8/87010fc8012a857871f166b4df0b99e255312072.png)

In CakePHP 4 and 5 when I look at Session in DebugKit I see `Auth.id` etc not `Auth.User.id`

 ![image](https://canada1.discourse-cdn.com/flex029/uploads/cakephp/original/2X/0/0fdc591893681fccc11755adce86b461888f0cf0.png)

---

<div class="post-metadata">

**Author:** ![webdeveloper](https://avatars.discourse-cdn.com/v4/letter/w/c4cdca/32.png) [@webdeveloper](https://discourse.cakephp.org/u/webdeveloper)\
**Post date:** [September 3, 2024, 1:48pm UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214/4 "2024-09-03T13:48:11Z")

</div>

Thank you. When I debug I do not see the session variables. But I can see the Flash.

```auto
        $this->session(['Auth.User.user_id' => 5]);
        dd($_SESSION);

```

debug:

```auto
PHPUnit 9.6.19 by Sebastian Bergmann and contributors.

E..S^ array:1 [
  "Flash" => array:1 [
    "flash" => array:1 [
      0 => array:4 [
        "message" => "New course code ABCD saved."
        "key" => "flash"
        "element" => "flash/success"
        "params" => []
      ]
    ]
  ]
]

```

---

<div class="post-metadata">

**Author:** ![KevinPfeifer](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/kevinpfeifer/32/3365_2.png) [@KevinPfeifer](https://discourse.cakephp.org/u/KevinPfeifer)\
**Post date:** [September 3, 2024, 2:13pm UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214/5 "2024-09-03T14:13:28Z")

</div>

You misunderstand how `$this->session()` works.

It sets the HTTP Sessions for the next Integration Test call (like `$this->get()` or `$this->post()`) but does NOT directly write to the `$_SESSION` superglobal.

---

<div class="post-metadata">

**Author:** ![webdeveloper](https://avatars.discourse-cdn.com/v4/letter/w/c4cdca/32.png) [@webdeveloper](https://discourse.cakephp.org/u/webdeveloper)\
**Post date:** [September 3, 2024, 2:17pm UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214/6 "2024-09-03T14:17:14Z")

</div>

> [@webdeveloper](#):
>
> `dd($_SESSION);`

Thank you.

Even then I don’t see the session I set

```auto
$this->session(['Auth.User.user_id' => 5]);
$this->enableRetainFlashMessages();
$this->get(['prefix' => 'XXX', 'controller' => 'ControllerName', 'action' => 'actionName']);
dd($_SESSION);

```

debug: I get only the flash message from actionName method

```auto
PHPUnit 9.6.19 by Sebastian Bergmann and contributors.

...S^ array:1 [
  "Flash" => array:1 [
    "flash" => array:1 [
      0 => array:4 [
        "message" => "Invalid course code"
        "key" => "flash"
        "element" => "flash/error"
        "params" => []
      ]
    ]
  ]
]

```

---

<div class="post-metadata">

**Author:** ![webdeveloper](https://avatars.discourse-cdn.com/v4/letter/w/c4cdca/32.png) [@webdeveloper](https://discourse.cakephp.org/u/webdeveloper)\
**Post date:** [September 3, 2024, 2:20pm UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214/7 "2024-09-03T14:20:42Z")

</div>

> [@KevinPfeifer](#):
>
> $\_SESSION

Ah, okay. I see what you meant! So I will not be able to see the ‘Auth’ session variable in the $\_SESSION superglobal.

---

<div class="post-metadata">

**Author:** ![KevinPfeifer](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/kevinpfeifer/32/3365_2.png) [@KevinPfeifer](https://discourse.cakephp.org/u/KevinPfeifer)\
**Post date:** [September 3, 2024, 2:34pm UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214/8 "2024-09-03T14:34:47Z")

</div>

what you do inside your integration tests doesn’t “bleed out” to your phpunit test

---

<div class="post-metadata">

**Author:** ![webdeveloper](https://avatars.discourse-cdn.com/v4/letter/w/c4cdca/32.png) [@webdeveloper](https://discourse.cakephp.org/u/webdeveloper)\
**Post date:** [September 3, 2024, 2:36pm UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214/9 "2024-09-03T14:36:09Z")

</div>

In my behavior.php file, I use the below to check the session variable I set in test

```auto
if (isset($_SESSION['Auth']['User']['user_id'])) {

```

test method:

```auto
 $this->session(['Auth.User.user_id' => 5]);

```

How can I rewrite this since `$this->session` will not be writing to `$_SESSION`

---

<div class="post-metadata">

**Author:** ![KevinPfeifer](https://yyz1.discourse-cdn.com/flex029/user_avatar/discourse.cakephp.org/kevinpfeifer/32/3365_2.png) [@KevinPfeifer](https://discourse.cakephp.org/u/KevinPfeifer)\
**Post date:** [September 3, 2024, 3:02pm UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214/10 "2024-09-03T15:02:11Z")

</div>

behaviors are part of the model, therefore they don’t have access to either the request nor the logged in user directly.

Usually you add [GitHub - UseMuffin/Footprint: CakePHP plugin to allow passing currently logged in user to model layer.](https://github.com/UseMuffin/Footprint) to your application and therefore have easy access to the logged in user inside your model via the options array.

Otherwise the only way you can access the logged in user inside your behavios is by passing down the logged in user to the method you are calling (e.g. inside your controller)

---

<div class="post-metadata">

**Author:** ![webdeveloper](https://avatars.discourse-cdn.com/v4/letter/w/c4cdca/32.png) [@webdeveloper](https://discourse.cakephp.org/u/webdeveloper)\
**Post date:** [September 3, 2024, 3:13pm UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214/11 "2024-09-03T15:13:26Z")

</div>

I think my flash message is overwriting the session i set. But I am not quite sure why.

I have this in my controller action

```auto
if (!isset($id)) {
            $this->Flash->error(__('Invalid id'));
            return $this->redirect(['prefix' => 'Admin', 'controller' => 'controllerName', 'action' => 'index']);
        }

```

my test method:

```auto
$this->session(['Auth.User.user_id' => 5]);

$this->enableRetainFlashMessages();

$this->get(['prefix' => 'Admin', 'controller' => 'controllerName', 'action' => 'controllerAction']);
dd($_SESSION);

```

debug:

```auto
PHPUnit 9.6.19 by Sebastian Bergmann and contributors.

...S^ array:1 [
  "Flash" => array:1 [
    "flash" => array:1 [
      0 => array:4 [
        "message" => "Invalid id"
        "key" => "flash"
        "element" => "flash/error"
        "params" => []
      ]
    ]
  ]
]

```

if I remove ` $this->Flash->error(__('Invalid id'));` from my controllerAction, on my debug, I get:

```auto
PHPUnit 9.6.19 by Sebastian Bergmann and contributors.

E..S^ array:2 [
  "Auth" => array:1 [
    "User" => array:57 [
      "user_id" => 5

```

---

<div class="post-metadata">

**Author:** ![webdeveloper](https://avatars.discourse-cdn.com/v4/letter/w/c4cdca/32.png) [@webdeveloper](https://discourse.cakephp.org/u/webdeveloper)\
**Post date:** [September 3, 2024, 3:29pm UTC](https://discourse.cakephp.org/t/session-data-in-phpunittest/12214/12 "2024-09-03T15:29:20Z")

</div>

Okay. not Flash, but the redirection after the flash is causing the problem.
