Skip to content

User Story: Session extension #14

@berilee

Description

@berilee

User story

As a user I want to have my session silently extended so when I return to the tab at a later time I don’t have to sign-in again.

  1. User signs in to dashboard example.rp.com
  2. User leaves dashboard open in a tab
  3. User returns 3 days later and they are still signed-in and the dashboard can update to the latest information.

Q: Does this require a refresh_token in order to get an extended id_token or access_token?

Q: How do multi page apps typically do token refresh?
Are they affected by third-party cookie deprecation?
Is it a top-level navigation to get a new token?

Context of the story

Consumer, Enterprise, EDU, Healthcare

Should this be considered sanctioned or unsanctioned tracking?

Unknown / TBD

Explicit list of parties involved

  • IDP
  • RP
  • User

Security considerations

  • How long does the session continue to extend for? Is it indefinite?
  • What happens if the session extension fails? Is the user redirected somewhere? Is the redirection automatic?

Complicating characteristics

[TBD]

Additional information

[N/A]

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions