replaced account data singleton with a session model

This commit is contained in:
2026-09-27 14:49:38 +02:00
parent 79b33ab248
commit 5e65c4671a
60 changed files with 1019 additions and 679 deletions
@@ -1,12 +1,13 @@
import 'package:dio/dio.dart';
import '../../../model/account_data.dart';
import '../../../session/session.dart';
import '../../../session/session_manager.dart';
import '../queries/auth_login/auth_login.dart';
import 'device_token_name.dart';
import 'token_storage.dart';
/// Adds the bearer token to outgoing Marianum-Connect requests and, on 401,
/// re-logs in once with the credentials in [AccountData] before retrying.
/// renews the token once before retrying.
class MarianumConnectAuthInterceptor extends Interceptor {
static const _retriedKey = 'mc_auth_retried';
@@ -87,25 +88,26 @@ class MarianumConnectAuthInterceptor extends Interceptor {
}
Future<bool> _performReLogin() async {
if (!AccountData().isPopulated()) return false;
final username = AccountData().getUsername();
final session = SessionManager().current;
if (session is! CredentialSession) return false;
final username = session.username;
// A background engine (widget task) keeps the account it loaded. When
// the app signed that account out, its revoked token answers 401 — a
// re-login would mint a fresh token for it into the shared keystore.
if (await AccountData().readStoredUsername() != username) return false;
if (await SessionManager().readStoredUsername() != username) return false;
try {
await _loginClient.run(
username: username,
password: AccountData().getPassword(),
password: session.password,
tokenName: await DeviceTokenName.resolve(),
);
} catch (_) {
if (await AccountData().readStoredUsername() == username) {
if (await SessionManager().readStoredUsername() == username) {
await _tokenStorage.clear();
}
return false;
}
final stored = await AccountData().readStoredUsername();
final stored = await SessionManager().readStoredUsername();
if (stored == username) return true;
// Signed out during the login: drop the orphaned token, unless another
// account already stored its own.