Skip to main content

Module revoke

Module revoke 

Source
Expand description

RFC 7009 token revocation — what “log out” actually means at the PDS.

Without this, signing out only drops the local row: the refresh token stays live at the authorization server until it expires on its own, so a stolen copy of the database still yields a working session long after the user believes they are out. The sidecar revoked; the Rust path has to as well.

Structs§

PreflightOptions
Operator choices for preflight, from the command line.
RevokeAllReport
What an operator revoke-all did, per subject DID.
RevokeContext
What a revocation needs beyond the session itself. Mirrors super::session::RefreshContext; aud is the issuer for both.

Enums§

Revocation
What happened at the authorization server. Never an Err at the call site: the caller has already decided to sign the user out, and the question is only whether the server was told too.

Functions§

fit_to_revoke
Whether runtime is the production client — the only one that can revoke production’s sessions. The first check preflight makes.
preflight
Prove, BEFORE anything is signed out, that this process holds the production client’s real secrets — not merely a codec and a key file.
revoke_all
Sign EVERY stored session out — the operator’s fleet-wide revoke (#257).
revoke_params
The form body for a revocation request, client credentials included.
sign_out
Sign a subject out: tell the authorization server, then drop the local row.
sign_out_discovering
Sign out, discovering the revocation endpoint from the session itself.
token_to_revoke
Which of a session’s two tokens to present, and its token_type_hint.