Skip to content

AuthSessionResult ​

What every flow that establishes a session returns: RegisterAsync, CompleteTwoFactorLoginAsync, RefreshSessionAsync, and CreateSessionAsync. A sign-in that opens one without a second factor carries it on AuthLoginResult.Session.

DANGER

User is the database entity. Never return it from an endpoint: it serializes with the password hash, the surrogate key, and any loaded sessions. Map it to a DTO that exposes only the fields the client needs.

Fields

AccessToken: string
The signed JWT to return to the client. Its lifetime comes from AccessTokenMinutes in the JWT package's configuration.

RefreshToken: string
The refresh token in plain text, the only copy that will ever exist; only its hash is stored. Put it in the refresh-token cookie rather than the response body.

User: TUser
The authenticated user, tracked by the context. It is the database entity and serializes with the password hash, the surrogate key, and any loaded sessions, so map it to a DTO before returning it.

Type signature ​

csharp
public sealed class AuthSessionResult<TUser> where TUser : AuthUser
{
    public required string AccessToken { get; init; }
    public required string RefreshToken { get; init; }
    public required TUser User { get; init; }
}

All packages are released under the MIT License.