3 ms·
I forgot the exact issue but if I recall it correctly, pwdless sessions are meant to be short lived sessions. I equally dislike reauthenticating my sessions eve
by muratsu 4y ago
I forgot the exact issue but if I recall it correctly, pwdless sessions are meant to be short lived sessions. I equally dislike reauthenticating my sessions every day
- satvikpendem 4y agoWhy would they be short-lived? Just send a refresh and access token like normal authentication, the only thing you're changing is whether the user authenticates from a password versus a link which has a unique identifier, they're both looked up from the database / in-memory cache all the same.