4 ms·
I'm having to deal with this stuff right now. Firebase stores their refresh token in local storage and that allows minting new session tokens once they expire,
by hobo_mark 3y ago
I'm having to deal with this stuff right now. Firebase stores their refresh token in local storage and that allows minting new session tokens once they expire, are they wrong? Is there any other way to remain signed in "forever"? (until logout or until token is revoked)
- vindex10 3y agoI didn't work with Firebase myself, isn't this something relevant? https://firebase.google.com/docs/auth/admin/manage-cookies https://firebase.google.com/docs/auth/admin/manage-cookies
- hobo_mark 3y agoThat is what I'm using but I have to authenticate again every few days. If I used the client library it would autorefresh the token periodically, but that stores the refresh token in local storage. Since that is something you recommend against, I was wondering why.
- vindex10 3y agoJust to be clear, I'm not a security expert in any way, just learned myself while building things. So here is what I'd refer to: https://stackoverflow.com/questions/44133536/is-it-safe-to-store-a-jwt-in-localstorage-with-reactjs https://stackoverflow.com/questions/44133536/is-it-safe-to-s... Regarding the Firebase, I see an open issue on this, so I guess we are not the only ones wondering :) https://github.com/firebase/quickstart-nodejs/issues/194 https://github.com/firebase/quickstart-nodejs/issues/194