1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
//! The session-state entry type and shared limits.
use ;
use Uuid;
/// Hard cap on a single entry's serialized JSON value, in bytes.
///
/// Conversation state is short-term working memory, not blob storage: an
/// oversized value is refused loudly ([`crate::error::AuthError::SessionError`])
/// rather than truncated or silently accepted. Enforced by
/// [`SessionState::set`](super::SessionState::set) before any backend write, so
/// both backends share one limit.
pub const MAX_SESSION_VALUE_BYTES: usize = 65_536;
/// The reserved key a thread's rolled-up summary is stored under.
///
/// When a [`Summarizer`](super::Summarizer) collapses a thread, every ordinary
/// entry is replaced by a single entry with this key. Ordinary writes may not
/// use it — [`SessionState::set`](super::SessionState::set) refuses it so a
/// caller cannot spoof or clobber a summary by hand.
pub const SUMMARY_KEY: &str = "_summary";
/// One durable key/value pair of per-thread conversation state.
///
/// The isolation boundary is the *caller-supplied* `session_id`: the server
/// derives it from the authenticated context (an MCP session, a user session),
/// never from a client-named field — the same application-layer keying
/// `_system.sessions` uses.