-
Notifications
You must be signed in to change notification settings - Fork 8
Open
Description
User story
As a user I want to have my session silently extended so when I return to the tab at a later time I don’t have to sign-in again.
- User signs in to dashboard example.rp.com
- User leaves dashboard open in a tab
- User returns 3 days later and they are still signed-in and the dashboard can update to the latest information.
Q: Does this require a refresh_token in order to get an extended id_token or access_token?
Q: How do multi page apps typically do token refresh?
Are they affected by third-party cookie deprecation?
Is it a top-level navigation to get a new token?
Context of the story
Consumer, Enterprise, EDU, Healthcare
Should this be considered sanctioned or unsanctioned tracking?
Unknown / TBD
Explicit list of parties involved
- IDP
- RP
- User
Security considerations
- How long does the session continue to extend for? Is it indefinite?
- What happens if the session extension fails? Is the user redirected somewhere? Is the redirection automatic?
Complicating characteristics
[TBD]
Additional information
[N/A]
Metadata
Metadata
Assignees
Labels
No labels