pub struct WebSessionManager { /* private fields */ }Expand description
Server-side session manager for web applications.
Maps opaque session IDs (UUIDs) to OAuth tokens with automatic refresh and idle-timeout eviction.
§Idle timeout
Sessions that have not been accessed for idle_timeout_secs (default: 1 hour)
are evicted during an amortized sweep that runs when the session count
exceeds sweep_threshold (default: 64).
§Usage
use pep::session_manager::WebSessionManager;
use pep::oidc_client::OidcClient;
let mgr = WebSessionManager::new(
OidcClient::new(),
"https://idm.example.com/oauth2/openid/pdt-api".to_string(),
"pdt-api".to_string(),
None,
"openid profile email".to_string(),
);
// After OAuth callback:
let session_id = mgr.create_session(&token_response).await.unwrap();
// Store `session_id` in an HttpOnly cookie.
// On subsequent requests:
let access_token = mgr.get_token(&session_id).await.unwrap();Implementations§
Source§impl WebSessionManager
impl WebSessionManager
Sourcepub fn new(
oidc_client: OidcClient,
issuer_url: String,
client_id: String,
client_secret: Option<String>,
scope: String,
) -> Self
pub fn new( oidc_client: OidcClient, issuer_url: String, client_id: String, client_secret: Option<String>, scope: String, ) -> Self
Create a new WebSessionManager with an in-memory store.
§Arguments
oidc_client— OIDC client for token refresh operations.issuer_url— OIDC issuer URL (used for discovery during refresh).client_id— OAuth2 client ID.client_secret— Optional client secret (for confidential clients).scope— OAuth2 scopes (used during refresh).
Sourcepub fn with_refresh_buffer(self, secs: u64) -> Self
pub fn with_refresh_buffer(self, secs: u64) -> Self
Set the refresh buffer (how many seconds before expiry to trigger a refresh).
Default: 60 seconds.
Sourcepub fn with_idle_timeout(self, secs: u64) -> Self
pub fn with_idle_timeout(self, secs: u64) -> Self
Set the idle timeout — sessions not accessed for this long are evicted.
Default: 3600 seconds (1 hour).
Sourcepub fn with_sweep_threshold(self, threshold: usize) -> Self
pub fn with_sweep_threshold(self, threshold: usize) -> Self
Set the sweep threshold — amortized cleanup runs when session count exceeds this number.
Default: 64.
Sourcepub async fn create_session(
&self,
token_response: &TokenResponse,
) -> Result<String>
pub async fn create_session( &self, token_response: &TokenResponse, ) -> Result<String>
Create a new session from a token response.
Generates a random UUID session ID, stores the tokens server-side, and returns the session ID to be stored in a browser cookie.
Important: The caller must keep the refresh_token from the
token response — this method stores it server-side so it can be
used for later refreshes.
Sourcepub async fn get_token(&self, session_id: &str) -> Result<String>
pub async fn get_token(&self, session_id: &str) -> Result<String>
Get a valid access token for the given session, refreshing if necessary.
Updates last_accessed on every successful call. Performs amortized
idle-session sweep when the session count exceeds the threshold.
§Returns
Ok(token)— A valid access token (possibly freshly refreshed).Err(PepError::AuthenticationRequired)— Session not found, idle timed out, or refresh failed. The caller should redirect to login.
Sourcepub async fn force_refresh(&self, session_id: &str) -> Result<String>
pub async fn force_refresh(&self, session_id: &str) -> Result<String>
Force-refresh the token for a session, ignoring the cache.
Use this when a caller knows the cached token is invalid (e.g. JWT validation failed with ExpiredSignature despite our expiry estimate saying there’s time left — clock skew between servers).
Sourcepub fn destroy_session(&self, session_id: &str) -> Result<()>
pub fn destroy_session(&self, session_id: &str) -> Result<()>
Destroy a session, removing it from the store.
Call this on logout to invalidate the session immediately.
Sourcepub fn session_count(&self) -> usize
pub fn session_count(&self) -> usize
Returns the current number of active sessions.
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for WebSessionManager
impl !UnwindSafe for WebSessionManager
impl Freeze for WebSessionManager
impl Send for WebSessionManager
impl Sync for WebSessionManager
impl Unpin for WebSessionManager
impl UnsafeUnpin for WebSessionManager
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more