@@ -142,24 +142,48 @@ import { createClient }...
- const session = await auth.getSession();
+ const token = await rotateJwtWithSecret(req);
if (!token) throw new AuthError(401);
- res.setHeader('x-session', session.id);
+ res.setHeader('x-session', token.sid);
+ await audit.log({ sid: token.sid, ts });
return next();
@@ -201,9 +225,17 @@ export async function...
- export const ttl = 3600;
+ export const ttl = env.SESSION_TTL ?? 900;
+ export const rotateEvery = ttl / 3;
@@ -142,24 +142,48 @@ import { createClient }...
- const session = await auth.getSession();
+ const token = await rotateJwtWithSecret(req);
if (!token) throw new AuthError(401);
- res.setHeader('x-session', session.id);
+ res.setHeader('x-session', token.sid);
+ await audit.log({ sid: token.sid, ts });
return next();
@@ -201,9 +225,17 @@ export async function...
- export const ttl = 3600;
+ export const ttl = env.SESSION_TTL ?? 900;
+ export const rotateEvery = ttl / 3;
@@ -142,24 +142,48 @@ import { createClient }...
- const session = await auth.getSession();
+ const token = await rotateJwtWithSecret(req);
if (!token) throw new AuthError(401);
- res.setHeader('x-session', session.id);
+ res.setHeader('x-session', token.sid);
+ await audit.log({ sid: token.sid, ts });
return next();
@@ -201,9 +225,17 @@ export async function...
- export const ttl = 3600;
+ export const ttl = env.SESSION_TTL ?? 900;
+ export const rotateEvery = ttl / 3;
@@ -142,24 +142,48 @@ import { createClient }...
- const session = await auth.getSession();
+ const token = await rotateJwtWithSecret(req);
if (!token) throw new AuthError(401);
- res.setHeader('x-session', session.id);
+ res.setHeader('x-session', token.sid);
+ await audit.log({ sid: token.sid, ts });
return next();
@@ -201,9 +225,17 @@ export async function...
- export const ttl = 3600;
+ export const ttl = env.SESSION_TTL ?? 900;
+ export const rotateEvery = ttl / 3;