Skip to main content

Module session_cache

Module session_cache 

Source
Expand description

Cache-aside snapshots of user-session validity.

Every userinfo and introspect call must confirm the token’s user session still exists in storage; that check used to cost two SQL queries per request. This module caches the answer under cache_keys::session(realm, sid) as a small JSON value:

  • positive: {"u": "<user_id>", "v": <u64 version>}, TTL [cache] read_cache_ttl_secs (default 60 s, 0 disables the cache entirely — pure-DB behavior);
  • negative: {"x":1} with a short TTL (absorbs replay floods of deleted-session tokens; forged sids are impossible because token signature validation runs before this layer).

Invalidation:

  • single-session deletes (logout, admin revoke, idle cleanup) call invalidate_session synchronously — revocation is immediate;
  • bulk per-user revocation (user delete, which DB-cascades sessions without touching Rust) bumps the sessv:{realm}:{user_id} counter via bump_user_session_version; cached snapshots carrying an older version are treated as misses and re-read from storage;
  • anything that still bypasses both (e.g. a realm delete cascade on a node that missed invalidation) is bounded by the positive TTL — the accepted staleness window, same class as Keycloak’s Infinispan invalidation latency. Realm deletes are additionally covered because resolve_issuer_realm invalidation makes the issuer unresolvable.

Cache outages degrade, never fail: every cache error falls back to the storage path with a WARN, so a Redis hiccup costs latency, not answers.

Structs§

SessionSnapshot
The validity-relevant slice of a user session.

Functions§

bump_user_session_version
Bump the per-user session-validity version counter (bulk revocation: user delete / logout-all). Every cached snapshot of this user’s sessions misses on its next read. No TTL: the counter must outlive any cached snapshot it invalidates. Best-effort: snapshots keep their TTL as the fail-safe bound if the bump fails.
invalidate_session
Drop a session’s cached snapshot after its deletion (logout, admin revoke, idle cleanup). Best-effort: the positive TTL bounds staleness if the delete fails.
invalidate_session_entry
invalidate_session over a bare cache reference — shared by callers that do not hold a full ServerState.
session_snapshot
Resolve a session’s validity snapshot, cache-aside.