LEG-01. AuthSessionPort.recover now takes the request's lifetime context, and the raw recovery helper returns data only. The sign-out notification moved to the site that adopts the result, so a recovery that answers after the deadline or a caller abort is observed and discarded instead of logging the user out of a request nobody is waiting on. LEG-02. The V2 client shares V3's credential admission validator instead of checking the allowed set alone. A bearer profile whose patch omits, empties, duplicates or corrupts Authorization now fails closed with zero fetches rather than dispatching an anonymous request under an authenticated profile. OPT-NET-01. A cursor loader rejection is re-thrown exactly as it is with no signal at all. Only a signal that has actually aborted classifies the outcome as PAGINATION_ABORTED, so a real upstream failure stops being filed as a user cancellation. OPT-NET-02. defineMutationIntent and the V3 admission site now share the single isValidIdempotencyKey authority, closing the drift that let a control character through intent definition. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
53 lines
1.6 KiB
TypeScript
53 lines
1.6 KiB
TypeScript
export type SessionState =
|
|
| "authenticated"
|
|
| "unauthenticated"
|
|
| "recovery-pending"
|
|
| "integration-failed";
|
|
|
|
export type SessionGateway = Readonly<{
|
|
getState(): SessionState;
|
|
subscribe(listener: () => void): () => void;
|
|
beginSignIn(returnTo?: string): Promise<void>;
|
|
signOut(): Promise<void>;
|
|
/**
|
|
* LEG-01. Recovery is part of a request's lifetime, so it receives the same
|
|
* context a credential attach does. The context is optional for one release
|
|
* to keep existing owners working; the transport races the signal either way,
|
|
* and a recovery that answers after the request already ended is observed but
|
|
* never turned into a user-visible sign-out.
|
|
*/
|
|
recover(
|
|
context?: CredentialOperationContext,
|
|
): Promise<"restored" | "no-session">;
|
|
}>;
|
|
|
|
export type CredentialRequestBinding = Readonly<{
|
|
origin: string;
|
|
method: string;
|
|
operationId: string;
|
|
}>;
|
|
|
|
export type CredentialPatch = Readonly<{
|
|
headers: Readonly<Record<string, string>>;
|
|
}>;
|
|
|
|
/**
|
|
* §8.5. The transport lifetime handed to a credential owner. A cooperative
|
|
* owner abandons its own work on abort; a non-cooperative one is still bounded
|
|
* because the transport races the same signal.
|
|
*/
|
|
export type CredentialOperationContext = Readonly<{
|
|
signal: AbortSignal;
|
|
deadlineAtMonotonicMs: number;
|
|
}>;
|
|
|
|
export type CredentialAttacher = Readonly<{
|
|
credentialPatch(
|
|
binding: CredentialRequestBinding,
|
|
context?: CredentialOperationContext,
|
|
): Promise<CredentialPatch>;
|
|
onUnauthenticated(): void;
|
|
}>;
|
|
|
|
export type AuthSessionPort = SessionGateway & CredentialAttacher;
|