In my proposal was support for transaction scope - ON COMMIT RESET clause should be ok
Could you update the wiki, both the proposal and the use-case implementation, to reflect this point?
Moreover, is there any actual use-case for non-transactional secure half-persistent session variables? AFAICS the "secure" part implies both permissions and transactional for the presented security-related use case. If there is no use case for these combined features, then ISTM that you should update to proposal so that the variables are always transactional, which is both simpler, more consistent, and I think more acceptable.
If you are transaction sensitive, then you have to be sensitive to subtransactions - then the work is much more complex.
Is there use case, when you would to play with transactions and variables and RESET is not enough?
Also, you used a TEMPORARY session variable in one implementation, but this is not described in the proposal, I think it is worth mentioning it there as well.