---
title: "Deprecation: #93023 - Reworked session handling"
manual: "TYPO3 Core Changelog"
version: "main"
permalink: "https://docs.typo3.org/permalink/changelog:changelog-deprecation-93023-reworkedsessionhandling"
source: "Changelog/11.0/Deprecation-93023-ReworkedSessionHandling.rst"
typo3-version: "11.0"
typo3-major: 11
type: "deprecation"
issue: 93023
forge: "https://forge.typo3.org/issues/93023"
tags: ["PHP-API", "FullyScanned", "ext:core"]
rendered: "2026-09-25T23:17:45+00:00"
---

# Deprecation: #93023 - Reworked session handling {#changelog-deprecation-93023-reworkedsessionhandling}

See [forge#93023](https://forge.typo3.org/issues/93023)

## Description {#description}

As described in [Breaking: #93023 - Reworked session handling](https://docs.typo3.org/permalink/changelog:changelog-breaking-93023-reworkedsessionhandling)
the whole session handling in the TYPO3 Core was reworked by moving it
out of the user authentication classes.

Therefore some properties and methods within `AbstractUserAuthentication`
and its subclasses have been marked as deprecated:

-   `\TYPO3\CMS\Core\Authentication\AbstractUserAuthentication->createSessionId()`
-   `\TYPO3\CMS\Core\Authentication\AbstractUserAuthentication->fetchUserSession()`

## Impact {#impact}

Accessing `id` or calling `isExistingSessionRecord()`
respectively `getSessionId()` will trigger a PHP `E_USER_DEPRECATED` error.

Calling `createSessionId()` or `fetchUserSession()` will not
trigger a PHP `E_USER_DEPRECATED` error but will still be reported by the extension
scanner.

## Affected Installations {#affected-installations}

All TYPO3 installations with custom extensions directly accessing or calling
the deprecated properties or methods.

## Migration {#migration}

Creating a new session is now handled by the `UserSessionManager`.
Therefore the identifier is set internally on creation of a new session
and should not longer be called directly. Use e.g.
`UserSessionManager->createAnonymousSession()` or
`UserSessionManager->regenerateSession()` to create a new session
and then access `UserSession->getIdentifier()`.

Use `UserSessionManager->isSessionPersisted()` instead of
`isExistingSessionRecord()` to check if a session is already persisted.

Use the `UserSessionManager` to create a new session and then directly
access the `UserSession` instead of calling `fetchUserSession()`.

Use `UserSession->getIdentifier()` instead of `getSessionId()`. To
access this information from an user authentication object, call
`$userAuthentication->getSession()->getIdentifier()`.

## Related {#related}

-   [Breaking: #93023 - Reworked session handling](https://docs.typo3.org/permalink/changelog:changelog-breaking-93023-reworkedsessionhandling)
-   [Feature: #93023 - Introduce UserSession and UserSessionManager](https://docs.typo3.org/permalink/changelog:changelog-feature-93023-introduceusersessionandusersessionmanager)
