3 ms·
Pocketbase doesn't maintain separate refresh and access tokens. Credit to the discussion behind this can be found here: https://github.com/pocketbase/pocketbase
by mannders 3y ago
Pocketbase doesn't maintain separate refresh and access tokens. Credit to the discussion behind this can be found here: https://github.com/pocketbase/pocketbase/discussions/2154#discussioncomment-5426111 https://github.com/pocketbase/pocketbase/discussions/2154#di...
This is essentially because Pocketbase commits to being a monolithic architecture. There's no need to pass around auth status to different microservices, because all relevant services are accessible locally.
It doesn't even store the auth tokens themselves on the server, as the clients are expected to store and handle them, which eventually do expire.
TL:DR, having a long lived refresh token is not more secure than just having a long lived auth token in the first place.
The pocketbase monolithic architecture is one of the primary reasons I am so excited about this technology. No it isn't appropriate where horizontal scaling is mission critical, but for the indie developer projects, having more microservices than users is just complexity for no reason.