Comments (7)
We can't put specific number for the token expiration time , it depends on your situation , just try to make it short as possible. Regards.
from api-security-checklist.
One approach is to have 2 tokens. A short one for api calls and a long one for reauthenticate the short token
from api-security-checklist.
Okay, though how does that solve anything? You still have a token with long expiration.
from api-security-checklist.
One aspect to consider token expiration is your usecase medical/banking services might want to invalidate after a "short" time of inactivity e.g 10minutes
If you run a social network about cat pics short may be different
from api-security-checklist.
Thanks for that input, too, but it doesn't seem to answer my question.
from api-security-checklist.
Its been always a trade off between user expierence and security. So it depends on your situation and what UX you can implement to avoid annoying users.
For me 5-10 minutes of inactivity is enough , and you can show box to extend session limit and refresh to token.
from api-security-checklist.
Maybe this discussion helps someone else, but its not what I was hoping for. The checklist still has the same item ("Make token expiration (TTL, RTTL) as short as possible."). 5-10min is definitely too short for the kind of products I'm working on - the only use case where that seems appropriate is online banking. Anyway, thanks for sharing.
from api-security-checklist.
Related Issues (20)
- Should add "Content-Disposition" to response header?
- Serbian translations HOT 1
- Should mention CORS
- In "README.md", "į°Ą" should be âįŽâ. HOT 3
- Question about "Don't auto-increment IDs. Use UUID instead." HOT 4
- "algorithm" in the JWT HOT 4
- Please pay attention to this repo again HOT 1
- Why "User own resource ID should be avoided. Use /me/orders instead of /user/654321/orders." ? HOT 4
- JWT token should be stored securely if they are used as auth for browser users.
- ## Query HOT 1
- Api
- OAuth referred to as AuthN HOT 5
- request integrity & replay HOT 1
- Cyber security HOT 1
- HTTP Headers
- Aps security
- Expand on the authentication suggestion
- Why should not use Auto Increment IDs and Use UUIDs instead? HOT 14
- Og
- Security Headers
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
đ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. đđđ
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google â¤ī¸ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from api-security-checklist.