Session class
A logical authentication context bound to a subject. Producers and consumers exchange Session-shaped data in challenge issuance, authentication responses, and introspection (whoami).
Constructors
-
Session({required String id, required String subject, required String issuedAt, required String expiresAt, List<
String> ? amr, String? acr, String? sessionKey, String? actor, String? absoluteExpiresAt, Ext? ext}) -
const
-
Session.fromJson(Map<
String, dynamic> json) -
Read this payload from a decoded JSON object.
factory
Properties
- absoluteExpiresAt → String?
-
The instant beyond which this session's
expiresAtMUST NOT be advanced, by auth/refresh/0.2 or by any other means — an absolute session lifetime set once at authentication and never moved forward. Consumers that impose no such ceiling beyond the session's own rollingexpiresAtomit this member; its absence is not itself a claim that the session is unbounded, only that this response does not state a bound. See auth/refresh/0.2 Conformance and Security & Privacy for the enforcement rule.final - acr → String?
-
Authentication Context Class Reference per [OIDC Core §2]. Profiles define their
own values; the recommended set is "aal1" (single-factor DID auth), "aal2" (a
second possession-or-biometric factor confirmed), and "aal3" (hardware-bound second
factor).
final
- actor → String?
-
The delegate's VID — the party whose
proofactually authenticated this session — when this session was established by a proxied login (auth/authenticate/0.3,payload.principalpresent and distinct fromissuer). Absent wheneversubjectauthenticated with its own key, including every auth/authenticate/0.1 and /0.2 session and an auth/authenticate/0.3 request whereprincipalis absent or equalsissuer. Carryingactorseparately fromsubjectis what lets an audit trail, a revocation, or a response to a compromised delegate name the true acting party without conflating it with the principal it acted for — see auth/authenticate/0.3 Security & Privacy (Correlation).final -
amr
→ List<
String> ? -
Authentication Methods References per [RFC 8176]. Typical values: "did"
(challenge-response), "passkey" (WebAuthn), "vta" (verifiable-trust agent
approval). Multi-factor sessions list every method used.
final
- expiresAt → String
-
ISO-8601 timestamp when the session ceases to be valid. Producers SHOULD refresh
before this time; consumers MUST reject after. A consumer honouring
absoluteExpiresAtMUST NOT advance this value past it, by refresh or any other means.final - ext → Ext?
-
Ecosystem-defined extension members per SPEC.md §4.5.1.
final
- hashCode → int
-
The hash code for this object.
no setterinherited
- id → String
-
Opaque, server-chosen session identifier. Stable for the lifetime of the session.
Consumers MUST treat the value as opaque; no structure is implied.
final
- issuedAt → String
-
ISO-8601 timestamp when the session was created.
final
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- sessionKey → String?
-
The did:key VID bound to this session by auth/authenticate/0.2 or 0.3, when the
producer registered one. Present here so introspection (auth/whoami,
auth/sessions/list) can show the binding a client already holds; it is descriptive,
not an additional grant — the binding, its scope and its lifetime are governed
entirely by the auth/authenticate specification version that established it. Absent
when the session was established without a session key, or by a specification
version that does not carry one.
final
- subject → String
-
The authenticated party's VID (typically a DID URL). For a session established by a
proxied login (auth/authenticate/0.3), this is the principal being authenticated
as — never the delegate that signed the authenticate document; see
actor.final
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toJson(
) → Map< String, dynamic> - Serialize to a JSON-encodable map, omitting absent members.
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited