session
client.session signs in through the identity provider, resumes after inactivity, and signs out. It also carries the browser extension’s page session.
signIn
signIn signs in through the identity provider and proves the device key at once. On the first session in the tenant, the SDK fetches and pins the backup key fingerprint.
signIn(): Promise<Session>func signIn() async throws -> Sessionsuspend fun signIn(): SessionReturns: The Session that opened.
Records: Nothing. Not a decision.
Errors
locked: the SDK could not unlock the device key.revoked: this device’s device certificate (card) is no longer active.release-below-floor: the application’s release is below the tenant’s version floor.contract-retired: the Seald Healthcare Cloud no longer serves this SDK’s Cloud API major.unreachable: the Seald Healthcare Cloud cannot be reached.trust-failed: a card or the identity provider fails its check against the trust root built into the SDK.fingerprint-mismatch: the backup key registration names a key other than the one the SDK pinned.canceled: the person did not complete the sign-in.
resume
resume unlocks the device key after inactivity and signs a fresh nonce. It makes no identity provider round trip unless the tenant requires one.
resume(): Promise<Session>func resume() async throws -> Sessionsuspend fun resume(): SessionReturns: The resumed Session.
Records: Nothing. Not a decision.
Errors: locked, sign-in-required if the tenant requires the identity provider on resume or the token’s refresh was refused, revoked, unreachable, canceled.
signOut
signOut sends the session’s manifest, ends the session and discards any offline lease.
signOut(): Promise<void>func signOut() async throwssuspend fun signOut()Returns: Nothing.
Records: Nothing. Not a decision.
bindPage
bindPage is for the browser extension. It carries the dashboard page’s session beside this device’s on every call made for the page. The SDK refuses the call when the two sessions name different people.
bindPage(pageSession: string | undefined): voidfunc bindPage(_ pageSession: String?)fun bindPage(pageSession: String?)Parameters
| Name | Type | Description |
|---|---|---|
pageSession | string, optional | The dashboard page’s session token, or none to unbind. |
Returns: Nothing.
Records: Nothing. Not a decision.
Types
SessionState
type SessionState = 'none' | 'open' | 'inactive' | 'offline' | 'ended';enum SessionState: String { case none, open, inactive, offline, ended }enum class SessionState { NONE, OPEN, INACTIVE, OFFLINE, ENDED }| Value | Meaning |
|---|---|
none | No session is open. |
open | A session is open and active. |
inactive | The session went inactive. Call resume(). |
offline | The Seald Healthcare Cloud is unreachable. The session is open under an offline lease. |
ended | The session ended, by signOut() or otherwise. |
Session
interface Session { person: Person; multiFactor: boolean; openedAt: Date; lifetimes: { inactivity: Seconds; tokenRefresh: Seconds; overall: Seconds };}struct Session { let person: Person let multiFactor: Bool let openedAt: Date let lifetimes: Session.Lifetimes}data class Session( val person: Person, val multiFactor: Boolean, val openedAt: Instant, val lifetimes: Lifetimes,)| Field | Type | Description |
|---|---|---|
person | Person | Who this session was opened for. |
multiFactor | boolean | Whether the sign-in included a multi-factor step. |
openedAt | Date | When the session opened. |
lifetimes | { inactivity, tokenRefresh, overall } | The tenant’s session lifetimes, in seconds. See Lifetimes below. |
Lifetimes
The tenant’s session lifetimes, as Session.lifetimes carries them. TypeScript writes it inline as { inactivity: Seconds; tokenRefresh: Seconds; overall: Seconds }.
lifetimes: { inactivity: Seconds; tokenRefresh: Seconds; overall: Seconds };extension Session { struct Lifetimes { let inactivity: TimeInterval let tokenRefresh: TimeInterval let overall: TimeInterval }}data class Lifetimes(val inactivity: Duration, val tokenRefresh: Duration, val overall: Duration)| Field | Type | Description |
|---|---|---|
inactivity | Seconds | How long the session tolerates inactivity before it goes inactive. |
tokenRefresh | Seconds | How often the SDK refreshes the identity provider’s token. |
overall | Seconds | The session’s overall lifetime. |
Sessions
interface Sessions { readonly state: SessionState; readonly current?: Session; signIn(): Promise<Session>; resume(): Promise<Session>; signOut(): Promise<void>; bindPage(pageSession: string | undefined): void;}class Sessions { var state: SessionState { get } var current: Session? { get }
func signIn() async throws -> Session func resume() async throws -> Session func signOut() async throws func bindPage(_ pageSession: String?)}class Sessions { val state: SessionState val current: Session?
suspend fun signIn(): Session suspend fun resume(): Session suspend fun signOut() fun bindPage(pageSession: String?)}| Field | Type | Description |
|---|---|---|
state | SessionState | The current session state. |
current | Session, optional | The open session, if any. |
signIn | () => Promise<Session> | See above. |
resume | () => Promise<Session> | See above. |
signOut | () => Promise<void> | See above. |
bindPage | (pageSession) => void | See above. |