Jump to content

Feature request: don't expire access token after 90 days


Recommended Posts

I run 4 apps/programs/sites which access GC via the API.

  1. It's a nuisance and time consuming to have to reauthorise them repeatedly.
  2. It decreases security:  rather than entering my (long random) password once on my phone, I have to save it in a note in case it expires when I'm away from home.
Link to comment

I visit Project-GC on 3 devices, and have Cachly running on 2.  Cachly now utilises Keychain so that’s fixed the password security, but that still leaves a multi-screen reauthorisation I have to go through twice a month — sometimes out in the field.

 

No other website I use requires incessant babysitting to keep my access tokens valid.  It’s good it doesn’t bother you guys, but it’s harder when you realise it doesn’t have to be like this.

  • Upvote 2
Link to comment

What will happen when API2 is launched officially? In GSAK I see "token is older than 1 hour > refreshing token". Does that mean token refresh is going to be automated (even more than in GSAK)?

I suppose that when using the API the token can be checked (it's already checked for validity)  and it's lifetime extended if membership type is still the same?

 

 

 

 

Link to comment
On ‎8‎/‎8‎/‎2018 at 3:44 AM, on4bam said:

What will happen when API2 is launched officially? In GSAK I see "token is older than 1 hour > refreshing token". Does that mean token refresh is going to be automated (even more than in GSAK)?

I suppose that when using the API the token can be checked (it's already checked for validity)  and it's lifetime extended if membership type is still the same?

 

 

 

 

I believe that apps will be able to renew the token without user intervention but am not positive on that as I have yet to implement the new user authorization in LonelyCache. From the documentation:

Quote

When the access token expires, the app can make a POST call into the OAuth service's token endpoint to exchange the refresh_token for a new access token without any additional authorize calls.

 

Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...