DeployBoard / DeployBoard/deployboard-python

Figure out jwt refresh token

Aberta
#1 0 comentários 0 reações 0 responsáveis Ver no GitHub
api enhancement web
Linguagem predominante
Python
Estrelas
10
Forks
1
Métricas de merge de PRs
Nenhum PR com merge em 30d

Descrição

Right now the jwt expires after a set time (8 hour default) and forces the user to re-authenticate, which I think is an acceptable balance between security and user experience.

The security concern is that if a jwt is leaked somehow, the individual that has the compromised jwt now has up to 8 hours to do harm.

I would like to be able to implement some type of refresh token system where the access token is valid for only a short time (maybe 30 minutes), then a refresh token would be sent back to the api to extend the jwt another 30 minutes.

I personally need to do a bit more research on the topic, but certainly welcome anyone with experience to provide input.

Guia de contribuição

Nenhum guia de contribuição indexado para este repositório

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.