Stateless vs. Stateful Sessions
By default, Rays Web Security assumes you are building a stateful web application (using session cookies). If you are building a modern API (e.g., React, Vue, Mobile App) that uses stateless tokens, you must tell the framework to operate in a stateless manner.
You can do this by using the Csrf().Disable() and SessionCreationPolicy() builder methods.
Session Creation Policies
The SessionCreationPolicy() builder provides several options to control when the framework provisions a session:
.Default()/.IfRequired(): Rays will create a Session only if required (the default behavior)..Always(): Rays will always create a Session..Never(): Rays will never proactively create a Session, but will use one if it already exists..Stateless(): Rays will strictly not configure or use a Session (ideal for JWT APIs).
Example: Stateless Configuration
func (this *RouteSecurityConfig) HttpSecurity() *HttpSecurity {
return (&HttpSecurityBuilder{}).
Csrf().Disable(). // CSRF protection is generally not needed for stateless APIs
SessionCreationPolicy().Stateless(). // Fluently instruct the framework to be stateless
AuthorizedHTTPRequests().
Paths("/api/public/**").PermitAll().
And().
AnyRequest().Authenticated().
Basic().
Build()
}