Configure how your WooGraphQL application handles different user types with SessionBehavior flags.
Session behaviors define how your application handles different user types and what features are enabled. Configure them when creating a TokenManager.
import { SessionBehavior } from '@woographql/session-utils';
Enables support for authenticated WordPress users alongside guest sessions.
What it does:
authToken and refreshToken lifecyclerefreshAuthToken callback to be providedUse when:
const tokenManager = new TokenManagerWithBrowserStorage({ ID: 'my-store', behavior: [SessionBehavior.withAuth], startSession: async (tokens) => { /* ... */ }, refreshAuthToken: async (refreshToken) => { /* Required for withAuth */ }, });
Requires authentication for all sessions. Guest sessions are not supported.
What it does:
isReady() to return truehasTokens() requires all three tokensUse when:
const tokenManager = new TokenManagerWithBrowserStorage({ ID: 'my-store', behavior: [SessionBehavior.authOnly], startSession: async (tokens) => { /* ... */ }, refreshAuthToken: async (refreshToken) => { /* Required */ }, });
Enables client session ID generation for device tracking and session handoff URLs.
What it does:
clientSessionId that identifies the deviceupdateSession callback to sync with serverUse when:
const tokenManager = new TokenManagerWithBrowserStorage({ ID: 'my-store', behavior: [SessionBehavior.withClientSession], startSession: async (tokens) => { /* ... */ }, updateSession: async (tokens, input) => { /* Required for withClientSession */ }, });
Behaviors are combined using an array. Common configurations:
No authentication support. Simplest configuration.
behavior: []
Token requirements:
sessionToken onlySupport both guest and authenticated sessions.
behavior: [SessionBehavior.withAuth]
Token requirements:
sessionToken alwaysauthToken and refreshToken when authenticatedAuth support plus client session for session dropoff URLs.
behavior: [SessionBehavior.withAuth, SessionBehavior.withClientSession]
Token requirements:
sessionToken alwaysauthToken and refreshToken when authenticatedclientSessionId alwaysMembers-only store with session dropoff.
behavior: [SessionBehavior.authOnly, SessionBehavior.withClientSession]
Token requirements:
| Method | No Behaviors | withAuth | authOnly | withClientSession |
|---|---|---|---|---|
hasTokens() | sessionToken | sessionToken + (auth if logged in) | All three | + clientSessionId |
isReady() | sessionToken valid | + authToken valid if logged in | All tokens valid | + clientSessionId valid |
initializeSession() | Fetches session | + Refreshes auth if needed | Throws if no refresh token | + Creates clientSessionId |
| Auto-renewal | None | Auth token every 10min | Auth token every 10min | + Client session every 45min |
| Behavior | startSession | updateSession | refreshAuthToken |
|---|---|---|---|
| (none) | Required | Optional | Not used |
withAuth | Required | Optional | Required |
authOnly | Required | Optional | Required |
withClientSession | Required | Required | Optional |
withAuth + withClientSession | Required | Required | Required |