Interface SessionStore
public interface SessionStore
Where HttpSessions are kept between requests.
Two are provided, chosen by cn1.session.store: memory (the
default) and db, which keeps them in the server's database so any
instance behind a load balancer can serve any client. Implement this for
another -- a cache server -- and pass it to Backend.Builder.sessionStore.
-
Method Summary
Modifier and TypeMethodDescriptiondefault ObjectconsumeAttribute(String id, String name) Atomically removes and returns an attribute from the stored session.voidForgets a session.The session with this id, or null when there is none or it expired.intpurgeExpired(long now) Drops every session that has expired bynow; answers how many.voidsave(HttpSession session, String previousId) Records a session after a request that created or changed it.intsize()How many sessions are kept, or -1 when that is expensive to know.
-
Method Details
-
load
The session with this id, or null when there is none or it expired.- Throws:
IOException
-
save
Records a session after a request that created or changed it. When its id changed,previousIdnames the entry to drop; otherwise it is null.- Throws:
IOException
-
delete
-
consumeAttribute
Atomically removes and returns an attribute from the stored session. Concurrent callers, including callers in other server instances, must receive a given value at most once. Used for single-use security challenges. Custom stores must implement this before serving passkey ceremonies; the default fails closed instead of emulating an unsafe load/save sequence.- Throws:
IOException
-
purgeExpired
Drops every session that has expired bynow; answers how many.- Throws:
IOException
-
size
int size()How many sessions are kept, or -1 when that is expensive to know.
-