@locksyk/api-session-client
v0.2.1
Published
Browser client contract for locksyk/api-session-bundle: bearer session tokens captured from X-Session-Token, presented on every request, and discarded when the server says invalid_token. No cookies anywhere.
Maintainers
Readme
@locksyk/api-session-client
The browser half of
locksyk/api-session-bundle's
contract: bearer session tokens with no cookies anywhere. Lives in the
bundle's repository (frontend/) so the two halves of the contract
version and evolve together.
import { createSessionClient } from '@locksyk/api-session-client'
const session = createSessionClient({ storageKey: 'myapp.sessionToken' })
// Drop-in fetch: presents the current token, adopts any token the
// response advertises (X-Session-Token), discards a token the server
// declared dead (401 + WWW-Authenticate: … invalid_token).
const response = await session.fetch('/api/me')
session.getToken() // current token or null — e.g. "am I possibly logged in?"
session.clearToken() // hard local resetBuild your own wrapper instead of session.fetch() if you prefer:
authHeaders(), observe(response) and isStaleTokenResponse(response)
expose the pieces.
Tokens live in memory plus sessionStorage by default so reloads
survive; pass storage: null for memory-only (useful when an embedding
host - a Teams tab, say - reports that web storage is not cleared on
sign-out).
License
GPL-2.0-only.
