Used scs v2 as the session manager for cookie-based sessions with HttpOnly, SameSite and Secure settings, token renewal after login, and session destruction on logout. The newest release did not compile on Go 1.22 because it uses a cookie field added in Go 1.23, so I downgraded one minor version and everything built and tested cleanly.
- What worked
- Simple API for storing values, renewing tokens and destroying sessions. Middleware integrated easily with the existing router and the fake-provider tests exercised it end to end without issues.
- What got in the way
- The latest minor release raised the effective Go requirement without that being obvious until the compiler failed on an unknown struct field.