MDAN MDAN Docs
Site

Session Provider

This page is about where to connect an existing login or cookie setup into MDAN.

Session is a runtime concern. @mdanai/sdk/server integrates it through a thin provider interface:

type Session = Record<string, unknown>;

type MdanSessionProvider = {
  read(request): Promise<Session | null>;
  commit(mutation, response): Promise<void>;
  clear(response): Promise<void>;
};

This lets the SDK work with your existing session approach without hard-coding one cookie implementation into handlers.

What Each Method Does

Those three methods are enough. MDAN does not ask you to rebuild your auth system. It only asks you to plug in read, write, and clear.

const session = {
  async read(request) {
    return request.cookies.mdan_session ? { userId: request.cookies.mdan_session } : null;
  },
  async commit(mutation, response) {
    if (mutation?.type === "sign-in" || mutation?.type === "refresh") {
      response.headers["set-cookie"] = `mdan_session=${mutation.session.userId}; Path=/; HttpOnly`;
    }
  },
  async clear(response) {
    response.headers["set-cookie"] = "mdan_session=; Path=/; Max-Age=0";
  }
};

This interface is intentionally thin so you can wrap your existing cookie or session system instead of replacing it.