#pragma once #include #include #include #include #include namespace svapi { /// Extract the token from an Authorization: Bearer header. std::optional bearerToken(const std::string& authHeader); /// Extract the value of a named cookie from a Cookie: header string. std::optional cookieValue(const std::string& cookieHeader, const std::string& name); /// Generate a 32-character hex token (16 random bytes via OpenSSL RAND_bytes). std::string randomToken(); /// In-memory session store: token → (apiKeyValue, expiry). class SessionStore { public: explicit SessionStore(std::chrono::minutes ttl); /// Create a new session for the given API key value, returns the token. std::string create(const std::string& apiKeyValue, std::chrono::system_clock::time_point now); /// Return the API key value for the token, or nullopt if missing/expired. std::optional keyFor(const std::string& token, std::chrono::system_clock::time_point now); /// Remove/invalidate a session token. void remove(const std::string& token); /// Update the TTL for future sessions. void setTtl(std::chrono::minutes ttl); private: struct Entry { std::string key; std::chrono::system_clock::time_point expiry; }; std::unordered_map sessions_; std::chrono::minutes ttl_; std::mutex m_; }; } // namespace svapi