DeployBoard / DeployBoard/deployboard-python
Figure out jwt refresh token
- 主要言語
- Python
- スター
- 10
- フォーク
- 1
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
Right now the jwt expires after a set time (8 hour default) and forces the user to re-authenticate, which I think is an acceptable balance between security and user experience.
The security concern is that if a jwt is leaked somehow, the individual that has the compromised jwt now has up to 8 hours to do harm.
I would like to be able to implement some type of refresh token system where the access token is valid for only a short time (maybe 30 minutes), then a refresh token would be sent back to the api to extend the jwt another 30 minutes.
I personally need to do a bit more research on the topic, but certainly welcome anyone with experience to provide input.
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
評価
この issue はまだ評価されていません。