@rosschiu/kiban-sdk
    Preparing search index...

    Interface Session

    OIDC/PKCE session handle returned by createSession.

    interface Session {
        buildLoginUrl(): Promise<string>;
        getAccessToken(): string | null;
        getTokens(): TokenSet | null;
        handleCallback(callbackUrl: string): Promise<TokenSet>;
        isAuthenticated(): boolean;
        login(): Promise<void>;
        logout(): void;
        refresh(): Promise<string | null>;
    }
    Index
    • Builds the login redirect URL and records the PKCE transaction, without navigating — useful for tests and for hosts that want to control navigation themselves.

      Returns Promise<string>

    • Current access token, or null when signed out. Synchronous — never triggers a refresh; pair with an ApiClient's refreshAccessToken hook (this session's refresh) for 401-triggered refresh.

      Returns string | null

    • Current TokenSet (all three tokens + expiry), or null when signed out. Synchronous, like getAccessToken().

      Returns TokenSet | null

    • Handles the OIDC callback URL (must contain code and state). Idempotent: a second invocation with the same code (React StrictMode double-effect) returns the same result instead of re-exchanging an already-consumed authorization code.

      Parameters

      • callbackUrl: string

      Returns Promise<TokenSet>

    • True when there is a current TokenSet that is still usable: its access token has not passed expiry (with a small clock-skew allowance), OR it carries a refresh token (an expired access token is refreshed by the next 401 — only an IdP-rejected refresh or logout() ends the session). Presence alone is not enough: an expired set without a refresh token is not authenticated. Synchronous, like getAccessToken(); never triggers a refresh.

      Returns boolean

    • Redirects the browser to Keycloak's authorization endpoint (PKCE S256).

      Returns Promise<void>

    • Clears session state (tokens; the host app's own SessionContext, if any, is its own responsibility to clear) and redirects to Keycloak's RP-initiated logout endpoint. A refresh() still in flight at that moment is abandoned: its result is never stored.

      Returns void

    • Refreshes the access token using the stored refresh token. Single-flight: concurrent callers share one in-flight network call. Resolves to the new access token, or null if refresh is impossible or fails. Only an IdP-rejected refresh (invalid/expired/revoked refresh token) clears the session; a network-failure rejection resolves to null but leaves the existing session state (including the refresh token) intact for a later retry. A successful refresh response that omits refresh_token keeps the previous one instead of discarding it.

      Returns Promise<string | null>