Monorepo for Tangled

appview/oauth: invalidate sessions if inactive for too long master

if sessions are inactive for too long, tokens will not be refreshed, and calling authorized xrpc methods will error out with invalid_grant. this changeset does two things: - tracks the last time a session was active using a new redis pair: `oauth:session_meta:<did>:<session>`, this is updated every time `SaveSession` is called - checks for session inactivity every time `GetSession` is called, and deletes the session if so this way, `GetSession` will never return a session with expired tokens. Signed-off-by: oppiliappan <me@oppi.li>


Author oppiliappan Committer Tangled Date Commit ee08cd02 Parent 8f17b7bd Change ID rnnvqlrq
+116 -12
2 changed files