Skip to content

[ENHANCEMENT] Implement Rotating Refresh Tokens #18

@Dan6erbond

Description

@Dan6erbond

Overview

Recog's security is compromised with regular long-lived refresh tokens due to the increased likelihood of a high-jacker being able to to make use of the token for a longer time. Rotating tokens ensure refresh tokens are invalidated quickly to avoid the effectiveness of such an attack.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions