Session object constructor. Typically called as follows:
const session = new Session(
{
clientAuthentication: getClientAuthenticationWithDependencies({})
},
"mySession"
);
The options enabling the correct instantiation of the session. Either both storages or clientAuthentication are required. For more information, see ISessionOptions.
A string uniquely identifying the session.
Readonly
eventsSession attribute exposing the EventEmitter interface, to listen on session events such as login, logout, etc.
Fetches data using available login information. If the user is not logged in, this will behave as a regular fetch
. The signature of this method is identical to the canonical fetch
.
Optional
init: RequestInitOptional
init: RequestInitOptional parameters customizing the request, by specifying an HTTP method, headers, a body, etc. Follows the WHATWG Fetch Standard.
Readonly
infoInformation regarding the current session.
Completes the login process by processing the information provided by the identity provider through redirect.
The URL of the page handling the redirect, including the query parameters — these contain the information to process the login.
Triggers the login process. Note that this method will redirect the user away from your app.
Optional
options: ILoginInputOptionsParameter to customize the login behaviour. In particular, two options are mandatory: options.oidcIssuer
, the user's identity provider, and options.redirectUrl
, the URL to which the user will be redirected after logging in their identity provider.
This method should redirect the user away from the app: it does not return anything. The login process is completed by handleIncomingRedirect
.
Logs the user out of the application.
There are 2 types of logout supported by this library,
app
logout and idp
logout.
App logout will log the user out within the application by clearing any session data from the browser. It does not log the user out of their Solid identity provider, and should not redirect the user away. App logout can be performed as follows:
await session.logout({ logoutType: 'app' });
IDP logout will log the user out of their Solid identity provider,
and will redirect the user away from the application to do so. In order
for users to be redirected back to postLogoutUrl
you MUST include the
postLogoutUrl
value in the post_logout_redirect_uris
field in the
Client ID Document.
IDP logout can be performed as follows:
await session.logout({
logoutType: 'idp',
// An optional URL to redirect to after logout has completed;
// this MUST match a logout URL listed in the Client ID Document
// of the application that is logged in.
// If the application is logged in with a Client ID that is not
// a URI dereferencing to a Client ID Document then users will
// not be redirected back to the `postLogoutUrl` after logout.
postLogoutUrl: 'https://example.com/logout',
// An optional value to be included in the query parameters
// when the IDP provider redirects the user to the postLogoutRedirectUrl.
state: "my-state"
});
Optional
options: ILogoutOptionsStatic
fromCreates a session from auth state information (code verifier and state) This is useful for continuing the auth code flow after storing the auth state in an external database in clustered deployments.
Object containing codeVerifier and state needed to continue the auth flow
Optional ID for the session, if not provided a random UUID will be generated
A Session instance with enough context to continue the auth code flow
Static
fromCreates a session from a set of tokens without requiring a full login flow. This is useful for scenarios where you already have tokens from another source and want to create an authenticated session directly.
The token set to use for authentication
Optional ID for the session, if not provided a random UUID will be generated
A Session instance
A Session object represents a user's session on an application. The session holds state, as it stores information enabling access to private resources after login for instance.