Expand description
RFC 7009 token revocation — what “log out” actually means at the PDS.
Without this, signing out only drops the local row: the refresh token stays live at the authorization server until it expires on its own, so a stolen copy of the database still yields a working session long after the user believes they are out. The sidecar revoked; the Rust path has to as well.
Structs§
- Preflight
Options - Operator choices for
preflight, from the command line. - Revoke
AllReport - What an operator revoke-all did, per subject DID.
- Revoke
Context - What a revocation needs beyond the session itself. Mirrors
super::session::RefreshContext;audis the issuer for both.
Enums§
- Revocation
- What happened at the authorization server. Never an
Errat the call site: the caller has already decided to sign the user out, and the question is only whether the server was told too.
Functions§
- fit_
to_ revoke - Whether
runtimeis the production client — the only one that can revoke production’s sessions. The first checkpreflightmakes. - preflight
- Prove, BEFORE anything is signed out, that this process holds the production client’s real secrets — not merely a codec and a key file.
- revoke_
all - Sign EVERY stored session out — the operator’s fleet-wide revoke (#257).
- revoke_
params - The form body for a revocation request, client credentials included.
- sign_
out - Sign a subject out: tell the authorization server, then drop the local row.
- sign_
out_ discovering - Sign out, discovering the revocation endpoint from the session itself.
- token_
to_ revoke - Which of a session’s two tokens to present, and its
token_type_hint.