Skip to main content

SessionStore

Struct SessionStore 

Source
pub struct SessionStore { /* private fields */ }
Expand description

Encrypts/decrypts session payloads with a per-store AEAD key.

Supports key rotation: encode always uses the primary key, while decode tries the primary first, then each retired fallback in order. This lets a deployment rotate JERRYCAN_SECRET without invalidating sessions/tokens minted under the previous key — the old key is moved to fallbacks until it is fully retired (dropped from the list), at which point its ciphertexts stop decrypting.

Implementations§

Source§

impl SessionStore

Source

pub fn new(key: &[u8; 32]) -> Self

Single-key store (no rotation). Equivalent to with_keys(key, &[]).

Source

pub fn with_keys(primary: &[u8; 32], fallbacks: &[[u8; 32]]) -> Self

Rotation-aware store: encode uses primary; decode tries primary then each entry of fallbacks in order. The first key that authenticates the ciphertext wins.

Source

pub fn encode<T: Serialize>(&self, value: &T) -> Result<String>

Serialize + encrypt to a base64url token (no padding).

Source

pub fn decode<T: DeserializeOwned>(&self, token: &str) -> Result<T>

Decrypt + deserialize. Tries the primary key, then each rotation fallback in order; the first key that authenticates wins. Any failure (bad base64, short input, AEAD rejection under every key, JSON shape) is JC0401 — an untrusted client value.

A Set-Cookie header value establishing the session (secure defaults).

A Set-Cookie header value clearing the session.

Extract the session cookie value from a Cookie request header. Public so sibling crates (and the fuzz-smoke suite) can exercise the parser.

Trait Implementations§

Source§

impl Clone for SessionStore

Source§

fn clone(&self) -> SessionStore

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V