Feat/token invalidation - #338
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the ✨ Finishing Touches🧪 Generate unit tests
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. CodeRabbit Commands (Invoked using PR/Issue comments)Type Other keywords and placeholders
CodeRabbit Configuration File (
|
44bd001 to
5e63f32
Compare
|
That looks nice! So if I understand it well, the validity of the tokens is stored in a redis db and we don't need to access the pg db at every request anymore ? In this case, it is indeed fine to have some data (other than user id) in the token. We will need to invalidate the token when we mutate some of this data. One consideration I have is the added |
Exactly. And we can also allow a true user logout as well using this approach. The generic that was added is the rust type system in action. More specifically we use traits and not specific types so we can easily tests using mocks and easily replace the specify trait In rust once you enter the generics realm you will end up with somewhat verbose syntax. I personally don't see it this way, I like how explicit the rust type system is but I can understand why people find it verbose 😂 |
|
I see, this makes sense! |
|
very nice! |
This reverts commit d22df40.
Continuation of this PR #335
PENDING add automated tests