Refactor session ID handling and improve error management

- Introduced `SessionId` newtype for validated session identifiers, ensuring safety against path traversal attacks.
- Updated session repository methods to accept `SessionId` instead of raw strings, enhancing type safety.
- Removed redundant error handling in repository methods by leveraging the new `Error` type from `zesdex_utils`.
- Simplified atomic JSON write operations by eliminating unnecessary error conversions.
- Enhanced integer casting with a new `CastOr` trait for safer narrowing conversions.
- Removed deprecated error handling code and consolidated error types across the codebase.
- Updated HTTP handlers to utilize the new session ID validation, improving overall robustness.
This commit is contained in:
asepharyana
2026-07-20 06:39:30 +07:00
parent ab1a54b72e
commit e9a8e93c83
39 changed files with 413 additions and 366 deletions
+3 -1
View File
@@ -8,6 +8,8 @@
//!
//! - [`SessionService`] — create, list, archive sessions
//! - [`OAuthService`] — start PKCE flow, complete code exchange, retrieve token
use zesdex_entities::domain::auth::SessionId;
use crate::domain::error::ServiceError;
use crate::domain::oauth::{OAuthConfig, OAuthToken};
use crate::domain::session::Session;
@@ -21,7 +23,7 @@ pub trait SessionService {
fn list_all(&self) -> Result<Vec<Session>, ServiceError>;
/// Archive a session by id (sets `archived = true`).
fn archive_session(&self, id: &str) -> Result<(), ServiceError>;
fn archive_session(&self, id: SessionId) -> Result<(), ServiceError>;
}
/// OAuth flow use-case boundary.