DeployBoard / DeployBoard/deployboard-python

Figure out jwt refresh token

オープン
#1 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
api enhancement web
主要言語
Python
スター
10
フォーク
1
PR マージ指標
30日以内にマージされた PR はありません

説明

Right now the jwt expires after a set time (8 hour default) and forces the user to re-authenticate, which I think is an acceptable balance between security and user experience.

The security concern is that if a jwt is leaked somehow, the individual that has the compromised jwt now has up to 8 hours to do harm.

I would like to be able to implement some type of refresh token system where the access token is valid for only a short time (maybe 30 minutes), then a refresh token would be sent back to the api to extend the jwt another 30 minutes.

I personally need to do a bit more research on the topic, but certainly welcome anyone with experience to provide input.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。