@rosschiu/kiban-sdk
    Preparing search index...

    Interface SessionConfig

    Construction options for createSession.

    interface SessionConfig {
        authOrigin: string;
        clientId: string;
        fetchFn?: {
            (input: URL | RequestInfo, init?: RequestInit): Promise<Response>;
            (input: string | URL | Request, init?: RequestInit): Promise<Response>;
        };
        navigate?: (url: string) => void;
        now?: () => number;
        persistTokens?: boolean;
        postLogoutRedirectUri?: string;
        realm: string;
        redirectUri: string;
        scope?: string;
        storage?: StorageAdapter;
    }
    Index
    authOrigin: string

    Gateway origin, e.g. https://127.0.0.1:8443. All OIDC endpoints are relative to this — the SDK never talks to Keycloak directly.

    clientId: string

    Public OIDC client id.

    fetchFn?: {
        (input: URL | RequestInfo, init?: RequestInit): Promise<Response>;
        (input: string | URL | Request, init?: RequestInit): Promise<Response>;
    }

    Injectable for tests; defaults to global fetch.

    Type Declaration

      • (input: URL | RequestInfo, init?: RequestInit): Promise<Response>
      • Parameters

        • input: URL | RequestInfo
        • Optionalinit: RequestInit

        Returns Promise<Response>

      • (input: string | URL | Request, init?: RequestInit): Promise<Response>
      • Parameters

        • input: string | URL | Request
        • Optionalinit: RequestInit

        Returns Promise<Response>

    navigate?: (url: string) => void

    Navigation hook for login()/logout(); defaults to window.location.assign. Injectable so tests never actually navigate.

    now?: () => number

    Clock injection for tests.

    persistTokens?: boolean

    Also persist the current TokenSet to storage (survives a page refresh) in addition to keeping it in memory. Still never localStorage — storage here is the same sessionStorage-or-injected adapter used for the PKCE transaction. Defaults to false (memory-only, the safer default). A persisted entry is only hydrated back if it still has the right shape and is still usable: not expired (a small clock-skew allowance applies), or expired but carrying a refresh token (the next 401 refreshes it); anything else is dropped rather than trusted.

    postLogoutRedirectUri?: string

    Where the browser lands after RP-initiated logout. Defaults to the app ORIGIN ROOT (derived from redirectUri's origin, e.g. https://app.test/) — never redirectUri itself, which is the login callback route and cannot handle a logout redirect (no code/state params).

    realm: string

    Keycloak realm name.

    redirectUri: string

    Where the browser lands after a successful login. Must be registered as a redirect URI on the client; same-origin/return-path sanitization is the host app's concern, not the SDK's.

    scope?: string

    Defaults to "openid".

    storage?: StorageAdapter

    Injectable transaction/token storage; defaults to sessionStorage (or an in-memory fallback when unavailable). Never defaults to localStorage.