Defines the scope of the caller to be used throughout the app.
The scope carries only the caller's user_id, never a cached %User{}
snapshot: a scope can outlive the request that built it (a socket stays open
for hours), so the user is always resolved fresh via user/1, which reads
through Gamend.Accounts.get_user/1's cache. This keeps mutable state
(lobby_id, online, is_admin) current instead of frozen at connect time.
A %Scope{} always represents a signed-in caller — for_user/1 returns
nil for a signed-out one — so a %Scope{} match implies a present user_id.
That caller may still be an anonymous account (a device id and nothing else,
User.anonymous?/1): a game client's, or the one the website gives a visitor
(GamendWeb.UserAuth.ensure_user/1). anonymous?/1 tells them apart.
authenticated_at is a session fact (from the session token, virtual on
User) that cannot be re-derived from the DB row, so it is carried on the
scope and merged back onto the freshly-resolved user by user/1 — this is
what sudo_mode? checks.
Summary
Functions
True when the caller is signed in with an anonymous account: no email and no sign-in provider, only a device id. False for a signed-out (nil) scope.
Creates a scope for the given user, or nil when signed out.
Resolves the caller's user fresh (cached), with the session's
authenticated_at merged back on. nil if the scope is nil or the user is gone.
The caller's id, or nil for a nil scope.
Functions
True when the caller is signed in with an anonymous account: no email and no sign-in provider, only a device id. False for a signed-out (nil) scope.
Creates a scope for the given user, or nil when signed out.
Resolves the caller's user fresh (cached), with the session's
authenticated_at merged back on. nil if the scope is nil or the user is gone.
The caller's id, or nil for a nil scope.