// The {did, handle, avatar} mirror of the OAuth session, kept in // chrome.storage.local for contexts that cannot run the OAuth client (the // worker) or want it without one (the popup on open). Separate from oauth.ts // so the worker can import it without pulling in the browser OAuth client — // and because the offscreen document that runs that client cannot write the // mirror itself: offscreen documents get no chrome.storage at all. import type { SessionInfo } from './types' export const SUB_KEY = 'oauth.sub' export const SESSION_KEY = 'session' /** * storage.local marker set when a session is dropped without the user asking * (refresh token expired or revoked remotely). The popup shows it once, so * being signed out has an explanation instead of looking like amnesia. */ export const SESSION_EXPIRED_KEY = 'sessionExpired' export async function getStoredSession(): Promise { const stored = await chrome.storage.local.get(SESSION_KEY) return stored[SESSION_KEY] as SessionInfo | undefined } /** A fresh sign-in also retires any pending expiry note. */ export async function saveSessionMirror(info: SessionInfo): Promise { await chrome.storage.local.set({ [SUB_KEY]: info.did, [SESSION_KEY]: info }) await chrome.storage.local.remove(SESSION_EXPIRED_KEY) } /** Deliberate sign-out: drop everything, including any expiry note. */ export async function clearSessionMirror(): Promise { await chrome.storage.local.remove([SUB_KEY, SESSION_KEY, SESSION_EXPIRED_KEY]) } /** The session died on its own: drop it but leave the one-shot expiry note. */ export async function markSessionExpired(): Promise { await chrome.storage.local.remove([SUB_KEY, SESSION_KEY]) await chrome.storage.local.set({ [SESSION_EXPIRED_KEY]: true }) }