4 ms·
How long would you consider reasonable before requiring the user to enter a password when clicking through an email? Basically, how long should the token be val
by draker 13y ago
How long would you consider reasonable before requiring the user to enter a password when clicking through an email? Basically, how long should the token be valid from a user perspective?
From a developer perspective I think unless you are comfortable with a 1-2 week token* (or longer depending on customer base) you could actually decrease conversion rates because you remove the features consistency.
Ex: a user is cleaning out emails, starts with the most recent and works their way back. Opens OkCupid message from 3 weeks ago because it was interesting, but the link doesn't work.
*I would appreciate further insight as to what is a normal length of time for tokens to be valid and the impact increasing the token expiration time might have on security.
- ultrafez 13y agoIn this situation the user would already be logged in from opening newer emails, so opening the older emails would use their existing session, even though the token has expired. Or if the user visits an old email without looking at a new email first, the user can just log in as usual.