Files
Oxicloud/src/domain/entities/session.rs
T

157 lines
4.2 KiB
Rust
Raw Normal View History

2026-02-14 01:29:34 +01:00
use chrono::{DateTime, Duration, Utc};
2025-03-20 09:22:31 +01:00
use uuid::Uuid;
#[derive(Debug, Clone)]
2025-03-20 09:22:31 +01:00
pub struct Session {
id: Uuid,
user_id: Uuid,
refresh_token: String,
expires_at: DateTime<Utc>,
ip_address: Option<String>,
user_agent: Option<String>,
created_at: DateTime<Utc>,
revoked: bool,
/// Groups all tokens issued from the same original login.
/// Replaying a revoked token from this family triggers full-family revocation.
family_id: Uuid,
2026-08-03 01:17:16 +02:00
/// ID token from the OIDC login exchange. Used as `id_token_hint` on the
/// RP-initiated logout URL so the IdP can terminate its own SSO session.
/// `None` for password / magic-link sessions.
oidc_id_token: Option<String>,
2026-08-03 08:00:13 +02:00
/// OIDC session identifier (sid claim). Populated only when the IdP
/// emits it. Enables per-device Back-Channel Logout — without it, a
/// BCL notification would revoke all of the user's sessions rather
/// than just the one that logged out on the far end.
oidc_sid: Option<String>,
2025-03-20 09:22:31 +01:00
}
impl Session {
pub fn new(
user_id: Uuid,
2025-03-20 09:22:31 +01:00
refresh_token: String,
ip_address: Option<String>,
user_agent: Option<String>,
expires_in_days: i64,
family_id: Uuid,
2025-03-20 09:22:31 +01:00
) -> Self {
if refresh_token.is_empty() {
panic!("Session refresh_token cannot be empty");
}
2025-03-20 09:22:31 +01:00
let now = Utc::now();
Self {
id: Uuid::new_v4(),
2025-03-20 09:22:31 +01:00
user_id,
refresh_token,
expires_at: now + Duration::days(expires_in_days),
ip_address,
user_agent,
created_at: now,
revoked: false,
family_id,
2026-08-03 01:17:16 +02:00
oidc_id_token: None,
2026-08-03 08:00:13 +02:00
oidc_sid: None,
2025-03-20 09:22:31 +01:00
}
}
2026-08-03 01:17:16 +02:00
/// Attach an OIDC ID token — call on sessions minted via the OIDC exchange.
/// The token is persisted with the session and re-emitted at logout as
/// `id_token_hint` so the IdP can end its own SSO session.
pub fn with_oidc_id_token(mut self, id_token: String) -> Self {
self.oidc_id_token = Some(id_token);
self
}
2026-08-03 08:00:13 +02:00
/// Attach the OIDC session identifier from the id_token's `sid` claim.
/// Optional even for OIDC sessions — only present when the IdP emits
/// sid (Keycloak requires "Backchannel Logout Session Required" on the
/// client). Without it, Back-Channel Logout falls back to sub-based
/// revocation which is coarser (all of the user's OxiCloud sessions).
pub fn with_oidc_sid(mut self, sid: String) -> Self {
self.oidc_sid = Some(sid);
self
}
#[allow(clippy::too_many_arguments)]
pub fn from_raw(
id: Uuid,
user_id: Uuid,
refresh_token: String,
expires_at: DateTime<Utc>,
ip_address: Option<String>,
user_agent: Option<String>,
created_at: DateTime<Utc>,
revoked: bool,
family_id: Uuid,
2026-08-03 01:17:16 +02:00
oidc_id_token: Option<String>,
2026-08-03 08:00:13 +02:00
oidc_sid: Option<String>,
) -> Self {
Self {
id,
user_id,
refresh_token,
expires_at,
ip_address,
user_agent,
created_at,
revoked,
family_id,
2026-08-03 01:17:16 +02:00
oidc_id_token,
2026-08-03 08:00:13 +02:00
oidc_sid,
}
}
2026-02-14 01:29:34 +01:00
2025-03-20 09:22:31 +01:00
// Getters
pub fn id(&self) -> Uuid {
self.id
2025-03-20 09:22:31 +01:00
}
2026-02-14 01:29:34 +01:00
pub fn user_id(&self) -> Uuid {
self.user_id
2025-03-20 09:22:31 +01:00
}
2026-02-14 01:29:34 +01:00
2025-03-20 09:22:31 +01:00
pub fn refresh_token(&self) -> &str {
&self.refresh_token
}
2026-02-14 01:29:34 +01:00
2025-03-20 09:22:31 +01:00
pub fn expires_at(&self) -> DateTime<Utc> {
self.expires_at
}
pub fn ip_address(&self) -> Option<&str> {
self.ip_address.as_deref()
}
pub fn user_agent(&self) -> Option<&str> {
self.user_agent.as_deref()
}
2026-02-14 01:29:34 +01:00
2025-03-20 09:22:31 +01:00
pub fn created_at(&self) -> DateTime<Utc> {
self.created_at
}
2026-02-14 01:29:34 +01:00
2025-03-20 09:22:31 +01:00
pub fn is_expired(&self) -> bool {
Utc::now() > self.expires_at
}
2026-02-14 01:29:34 +01:00
2025-03-20 09:22:31 +01:00
pub fn is_revoked(&self) -> bool {
self.revoked
}
2026-02-14 01:29:34 +01:00
2025-03-20 09:22:31 +01:00
pub fn revoke(&mut self) {
self.revoked = true;
}
pub fn family_id(&self) -> Uuid {
self.family_id
}
2026-08-03 01:17:16 +02:00
pub fn oidc_id_token(&self) -> Option<&str> {
self.oidc_id_token.as_deref()
}
2026-08-03 08:00:13 +02:00
pub fn oidc_sid(&self) -> Option<&str> {
self.oidc_sid.as_deref()
}
2026-02-14 01:29:34 +01:00
}