api icon indicating copy to clipboard operation
api copied to clipboard

Revisit auth token refresh & expiry

Open archived-m opened this issue 8 years ago • 1 comments

Mobile users should not have to log in as much as they have to. Check & follow best practices for authentication

archived-m avatar Sep 08 '17 17:09 archived-m

Mobile tokens should never expire or last for a very long time, so I'd set a request header in the mobile app that we verify server-side. We can then determine token expiry time based on who requested it.

archived-m avatar Dec 11 '17 13:12 archived-m