pub struct SessionHandler<Store> { /* private fields */ }Expand description
§Handler to enable sessions.
See crate-level docs for an overview of this crate’s approach to sessions and security.
Implementations§
Source§impl<Store: SessionStore> SessionHandler<Store>
impl<Store: SessionStore> SessionHandler<Store>
Sourcepub fn new(store: Store, secret: impl AsRef<[u8]>) -> Self
pub fn new(store: Store, secret: impl AsRef<[u8]>) -> Self
Constructs a SessionHandler from the given
async_session::SessionStore and secret.
The secret MUST be at least 32 bytes long, and MUST be cryptographically random to be
secure. It is recommended to retrieve this at runtime from the environment instead of
compiling it into your application.
§Panics
SessionHandler::new will panic if the secret is fewer than 32 bytes.
§Defaults
The defaults for SessionHandler are:
- cookie path: “/”
- cookie name: “trillium.sid”
- session ttl: one day
- same site: lax
- save unchanged: enabled
- older secrets: none
§Customization
Although the above defaults are appropriate for most applications, they can be overridden. Please be careful changing these settings, as some of them can weaken your application’s security:
use trillium_cookies::{CookiesHandler, cookie::SameSite};
use trillium_sessions::{MemoryStore, SessionHandler};
// this logic will be unique to your deployment
let secrets_var = std::env::var("TRILLIUM_SESSION_SECRETS").unwrap();
let session_secrets = secrets_var.split(' ').collect::<Vec<_>>();
let handler = (
CookiesHandler::new(),
SessionHandler::new(MemoryStore::new(), session_secrets[0])
.with_cookie_name("custom.cookie.name")
.with_cookie_path("/some/path")
.with_cookie_domain("trillium.rs")
.with_same_site_policy(SameSite::Strict)
.with_session_ttl(Some(Duration::from_secs(1)))
.with_older_secrets(&session_secrets[1..])
.without_save_unchanged(),
);Sourcepub fn with_store_error_handler(self, handler: impl Handler) -> Self
pub fn with_store_error_handler(self, handler: impl Handler) -> Self
Sets the handler that runs when the session store cannot be reached.
The default halts with a Status::ServiceUnavailable, because continuing would serve
the request as though the visitor had no session and then mint a replacement one,
orphaning the session they actually have and logging them out for good rather than for the
duration of the outage.
The provided handler runs with a SessionStoreError in conn state. If it halts, the
request ends there; if it does not, the request proceeds with an empty session, which is
the behavior an application that only uses sessions for optional personalization may
prefer. Passing the noop handler () selects that behavior directly.
// serve anonymous traffic through a session store outage
SessionHandler::new(MemoryStore::new(), secret).with_store_error_handler(());Sets a cookie path for this session handler. The default for this value is “/”
Sourcepub fn with_session_ttl(self, session_ttl: Option<Duration>) -> Self
pub fn with_session_ttl(self, session_ttl: Option<Duration>) -> Self
Sets a session ttl.
This will be used both for the cookie expiry and also for the session-internal expiry.
The default for this value is one day. Set this to None to not set a cookie or session expiry. This is not recommended.
Sets the name of the cookie that the session is stored with or in.
If you are running multiple trillium applications on the same domain, you will need different values for each application. The default value is “trillium.sid”
Sourcepub fn without_save_unchanged(self) -> Self
pub fn without_save_unchanged(self) -> Self
Disables the save_unchanged setting.
When save_unchanged is enabled, a session will cookie will always be set. With
save_unchanged disabled, the session data must be modified from the Default value in
order for it to save. If a session already exists and its data unmodified in the course of a
request, the session will only be persisted if save_unchanged is enabled.
Sourcepub fn with_same_site_policy(self, policy: SameSite) -> Self
pub fn with_same_site_policy(self, policy: SameSite) -> Self
Sets the same site policy for the session cookie.
The default is SameSite::Lax, which withholds the session cookie from the cross-site
requests that carry csrf risk — form submissions and subresource loads — while still
sending it when someone follows a link to the application from elsewhere.
SameSite::Strict additionally withholds it on top-level navigation, so a visitor
arriving from a link in an email or a search result arrives without their session and has
to navigate again to get one. That trade is usually worth making only for a second cookie
gating high-value operations, not for the session itself.
SameSite::None disables the protection entirely and requires a secure cookie.
See MDN on SameSite for more information about this setting.
Sets the domain of the cookie.
Sourcepub fn with_older_secrets(self, secrets: &[impl AsRef<[u8]>]) -> Self
pub fn with_older_secrets(self, secrets: &[impl AsRef<[u8]>]) -> Self
Sets optional older signing keys that will not be used to sign cookies, but can be used to validate previously signed cookies.
Trait Implementations§
Source§impl<Store: SessionStore> Debug for SessionHandler<Store>
impl<Store: SessionStore> Debug for SessionHandler<Store>
Source§impl<Store: SessionStore> Handler for SessionHandler<Store>
impl<Store: SessionStore> Handler for SessionHandler<Store>
Source§async fn run(&self, conn: Conn) -> Conn
async fn run(&self, conn: Conn) -> Conn
Source§async fn init(&mut self, info: &mut Info)
async fn init(&mut self, info: &mut Info)
Source§async fn before_send(&self, conn: Conn) -> Conn
async fn before_send(&self, conn: Conn) -> Conn
Source§fn has_upgrade(&self, upgrade: &Upgrade) -> bool
fn has_upgrade(&self, upgrade: &Upgrade) -> bool
Handler::upgrade. The first handler that responds true to this will receive
ownership of the trillium::Upgrade in a subsequent call to
Handler::upgradeSource§fn upgrade(&self, upgrade: Upgrade) -> impl Future<Output = ()> + Send
fn upgrade(&self, upgrade: Upgrade) -> impl Future<Output = ()> + Send
Handler::has_upgrade and will
only be called once for this upgrade. There is no return value, and this function takes
exclusive ownership of the underlying transport once this is called. You can downcast
the transport to whatever the source transport type is and perform any non-http protocol
communication that has been negotiated. You probably don’t want this unless you’re
implementing something like websockets. Please note that for many transports such as
TcpStreams, dropping the transport (and therefore the Upgrade) will hang up /
disconnect.