FAForever / FAForever/website

Passport refresh token if stale

Open
#478 0 comments 0 reactions 1 assignee Claimed by @fcaps View on GitHub
Bug
Dominant language
JavaScript
Stars
23
Forks
37
PR merge metrics
No merged PRs in 30d

Description

The website session is longer than the token ttl from hydra, so you can be logged in while your token is outdated.
To combat this we need some automatic check if the token is stale and refresh it if possible.

For axios it could look like:
````
instance.interceptors.request.use(config => {
if (token.expired()) {
token = token.refresh()
}

config.headers['Authorization'] = `Bearer ${token.token.access_token}`;
return config;
});
````

open questions:
- what if we cannot refresh? maybe throw an exception that can trigger client redirect to login?
- how to make this globally available? maybe some global axiosClient?
- how to implement this in tiny steps

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.