Expand description
Cache-aside snapshots of user-session validity.
Every userinfo and introspect call must confirm the token’s user
session still exists in storage; that check used to cost two SQL queries
per request. This module caches the answer under
cache_keys::session(realm, sid) as a small JSON value:
- positive:
{"u": "<user_id>", "v": <u64 version>}, TTL[cache] read_cache_ttl_secs(default 60 s,0disables the cache entirely — pure-DB behavior); - negative:
{"x":1}with a short TTL (absorbs replay floods of deleted-session tokens; forged sids are impossible because token signature validation runs before this layer).
Invalidation:
- single-session deletes (logout, admin revoke, idle cleanup) call
invalidate_sessionsynchronously — revocation is immediate; - bulk per-user revocation (user delete, which DB-cascades sessions
without touching Rust) bumps the
sessv:{realm}:{user_id}counter viabump_user_session_version; cached snapshots carrying an older version are treated as misses and re-read from storage; - anything that still bypasses both (e.g. a realm delete cascade on a
node that missed invalidation) is bounded by the positive TTL —
the accepted staleness window, same class as Keycloak’s Infinispan
invalidation latency. Realm deletes are additionally covered because
resolve_issuer_realminvalidation makes the issuer unresolvable.
Cache outages degrade, never fail: every cache error falls back to the storage path with a WARN, so a Redis hiccup costs latency, not answers.
Structs§
- Session
Snapshot - The validity-relevant slice of a user session.
Functions§
- bump_
user_ session_ version - Bump the per-user session-validity version counter (bulk revocation: user delete / logout-all). Every cached snapshot of this user’s sessions misses on its next read. No TTL: the counter must outlive any cached snapshot it invalidates. Best-effort: snapshots keep their TTL as the fail-safe bound if the bump fails.
- invalidate_
session - Drop a session’s cached snapshot after its deletion (logout, admin revoke, idle cleanup). Best-effort: the positive TTL bounds staleness if the delete fails.
- invalidate_
session_ entry invalidate_sessionover a bare cache reference — shared by callers that do not hold a fullServerState.- session_
snapshot - Resolve a session’s validity snapshot, cache-aside.