smswithoutborders/SMSWithoutBorders.com

[staging] Rebooted PC but account remained logged in

Closed this issue · 5 comments

[staging] Rebooted PC but account remained logged in

@sherlock this is expected if you didn't logout and your session is still valid (2h)

Let's reduce that to 30 minutes

Its a config you can change on the BE

There is a security vulnerability here, how is the FE handling it away from the BE?

If the user makes any request after their session expires a 401 is thrown and they are logged immediately