Skip to content

session

client.session signs in through the identity provider, resumes after inactivity, and signs out. It also carries the browser extension’s page session.

signIn

signIn signs in through the identity provider and proves the device key at once. On the first session in the tenant, the SDK fetches and pins the backup key fingerprint.

signIn(): Promise<Session>

Returns: The Session that opened.

Records: Nothing. Not a decision.

Errors

  • locked: the SDK could not unlock the device key.
  • revoked: this device’s device certificate (card) is no longer active.
  • release-below-floor: the application’s release is below the tenant’s version floor.
  • contract-retired: the Seald Healthcare Cloud no longer serves this SDK’s Cloud API major.
  • unreachable: the Seald Healthcare Cloud cannot be reached.
  • trust-failed: a card or the identity provider fails its check against the trust root built into the SDK.
  • fingerprint-mismatch: the backup key registration names a key other than the one the SDK pinned.
  • canceled: the person did not complete the sign-in.

resume

resume unlocks the device key after inactivity and signs a fresh nonce. It makes no identity provider round trip unless the tenant requires one.

resume(): Promise<Session>

Returns: The resumed Session.

Records: Nothing. Not a decision.

Errors: locked, sign-in-required if the tenant requires the identity provider on resume or the token’s refresh was refused, revoked, unreachable, canceled.

signOut

signOut sends the session’s manifest, ends the session and discards any offline lease.

signOut(): Promise<void>

Returns: Nothing.

Records: Nothing. Not a decision.

bindPage

bindPage is for the browser extension. It carries the dashboard page’s session beside this device’s on every call made for the page. The SDK refuses the call when the two sessions name different people.

bindPage(pageSession: string | undefined): void

Parameters

NameTypeDescription
pageSessionstring, optionalThe dashboard page’s session token, or none to unbind.

Returns: Nothing.

Records: Nothing. Not a decision.

Types

SessionState

type SessionState = 'none' | 'open' | 'inactive' | 'offline' | 'ended';
ValueMeaning
noneNo session is open.
openA session is open and active.
inactiveThe session went inactive. Call resume().
offlineThe Seald Healthcare Cloud is unreachable. The session is open under an offline lease.
endedThe session ended, by signOut() or otherwise.

Session

interface Session {
person: Person;
multiFactor: boolean;
openedAt: Date;
lifetimes: { inactivity: Seconds; tokenRefresh: Seconds; overall: Seconds };
}
FieldTypeDescription
personPersonWho this session was opened for.
multiFactorbooleanWhether the sign-in included a multi-factor step.
openedAtDateWhen the session opened.
lifetimes{ inactivity, tokenRefresh, overall }The tenant’s session lifetimes, in seconds. See Lifetimes below.

Lifetimes

The tenant’s session lifetimes, as Session.lifetimes carries them. TypeScript writes it inline as { inactivity: Seconds; tokenRefresh: Seconds; overall: Seconds }.

lifetimes: { inactivity: Seconds; tokenRefresh: Seconds; overall: Seconds };
FieldTypeDescription
inactivitySecondsHow long the session tolerates inactivity before it goes inactive.
tokenRefreshSecondsHow often the SDK refreshes the identity provider’s token.
overallSecondsThe session’s overall lifetime.

Sessions

interface Sessions {
readonly state: SessionState;
readonly current?: Session;
signIn(): Promise<Session>;
resume(): Promise<Session>;
signOut(): Promise<void>;
bindPage(pageSession: string | undefined): void;
}
FieldTypeDescription
stateSessionStateThe current session state.
currentSession, optionalThe open session, if any.
signIn() => Promise<Session>See above.
resume() => Promise<Session>See above.
signOut() => Promise<void>See above.
bindPage(pageSession) => voidSee above.