session

Creates a typed Session authentication scheme with a principal type P and a session type S.

The session value S is validated and mapped to a route principal P. Install the scheme with io.ktor.server.routing.Route.install or io.ktor.server.application.Application.install before protecting routes with authenticateWith.

data class UserSession(val username: String)
data class User(val name: String)

val sessionAuth = session<UserSession, User>("user-session") {
validate { session -> User(session.username) }
}

routing {
install(sessionAuth)
get("/login") {
sessionAuth.setSession(UserSession("alice"))
call.respondRedirect("/me")
}
authenticateWith(sessionAuth) {
get("/me") {
call.respondText("${call.session.username}:${call.principal.name}")
}
}
}

Report a problem

Return

a typed session authentication scheme.

Parameters

name

name that identifies the Session authentication scheme.

configure

configures Session authentication for this scheme.

Type Parameters

S

the stored session type.

P

the principal type exposed to authenticated routes.


inline fun <T : Any> AuthenticationConfig.session(name: String? = null)(source)
fun <T : Any> AuthenticationConfig.session(name: String? = null, kClass: KClass<T>)(source)
inline fun <T : Any> AuthenticationConfig.session(name: String? = null, noinline configure: SessionAuthenticationProvider.Config<T>.() -> Unit)(source)

Installs the session Authentication provider. This provider provides the ability to authenticate a user that already has an associated session.

To learn how to configure the session provider, see Session authentication.

Report a problem


inline fun <T : Any> AuthenticationConfig.session(name: String?, description: String?, kClass: KClass<T>, configure: SessionAuthenticationProvider.Config<T>.() -> Unit)(source)

Installs the session Authentication provider with description. This provider provides the ability to authenticate a user that already has an associated session.

To learn how to configure the session provider, see Session authentication.

Report a problem


Authenticated session captured for the current session-protected typed route.

Assigning this property updates the stored session and the value exposed in the current route handler.

Report a problem