4 ms·
Unless I've missed something, it's worse than that: even if you do verify the token, it only lasts for ten minutes, so you are obligated to tie it to some other
by jbmsf 7y ago
Unless I've missed something, it's worse than that: even if you do verify the token, it only lasts for ten minutes, so you are obligated to tie it to some other form of auth unless you want your users to re-authenticate every ten minutes.
However many developers can correctly follow the meager instructions to validate a token, the number who will properly implement a full auth system is even smaller...
- SahAssar 7y agoWell, it is called "Sign in with apple", not "Sessions with apple". Keeping sessions in a secure way is on the developer.