specs/auth/refresh/v0_2/payload library

Classes

Payload
Exchange a refresh token for a new access token (and optionally a new refresh token). 0.2 adds no new payload member: it accepts an optional framework proof made by a session key bound to the session at auth/authenticate/0.2 or 0.3, presented alongside — never instead of — the refresh token, and it never advances a session's expiresAt past its absoluteExpiresAt. See Conformance and Security & Privacy.
Response
Issued by the auth service when the presented refresh token is valid. Carried in a Trust Task document whose type is https://trusttasks.org/spec/auth/refresh/0.2#response.
Session
A logical authentication context bound to a subject. Producers and consumers exchange Session-shaped data in challenge issuance, authentication responses, and introspection (whoami).
TokenBundle
An access token (typically short-lived JWT) paired with an optional refresh token (typically long-lived opaque string). The shapes follow OAuth 2.0 (RFC 6749 §5.1) conventions but are not coupled to any particular OAuth profile.

Constants

payloadSchemaJson → const String
This specification's payload schema, as JSON text.
responsePayloadSchemaJson → const String
As payloadSchemaJson, for the success-response variant.
responseSpec → const SpecPolicy
The SPEC §7.2 policy for the success-response variant.
responseTypeUri → const String
The success-response form of typeUri (SPEC §4.4.1).
spec → const SpecPolicy
The SPEC §7.2 policy for the request variant, taken from this specification's front matter.
typeUri → const String
The Trust Task type URI this library's Payload is carried under.

Typedefs

Ext = Map<String, dynamic>
Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.