@lancedb/lancedb • Docs
@lancedb/lancedb / OAuthSession
Class: OAuthSession¶
Explicit OAuth session lifecycle for the persistent token cache: eager
login, non-secret status, and local logout.
A session is built from the same OAuthConfig used to connect
(including its tokenCache options). A connection created with the same
configuration shares the cache, so logging in here prepares tokens for
later processes without any database request.
login always runs the configured interactive flow and replaces the cached
session (the most recent login wins). logout removes only the local
credential; it does not revoke anything with the provider and does not sign
out of a browser SSO session.
Example¶
const config: OAuthConfig = {
issuerUrl: "https://issuer.example.com",
clientId: "my-app",
scopes: ["openid", "offline_access"],
flow: OAuthFlowType.DeviceCode,
tokenCache: { cacheDir: "/tmp/my-app/oauth-cache" },
};
const session = new OAuthSession(config);
const status = await session.login();
Constructors¶
new OAuthSession()¶
Create a session manager for the given OAuth configuration.
Parameters¶
- config:
OAuthConfig
Returns¶
Methods¶
login()¶
Eagerly run the configured authentication flow and store the session.
A successful login always replaces any prior cached session for this
identity; if the provider does not issue a refresh token (for example
without offline_access), the previous record is removed and the status
reports refreshable == false.
Returns¶
Promise<SessionStatus>
logout()¶
Remove the matching local cached credential.
This only deletes the local cache entry. It does not revoke the refresh
token with the provider and does not sign out of a browser SSO session.
Repeated calls succeed; removed reports whether a credential existed.
Returns¶
Promise<SessionLogout>
status()¶
Report whether a matching cached session exists, with safe metadata.
This never contacts the identity provider and never exposes token values.
Returns¶
Promise<SessionStatus>