Skip to content

fix: update access token cookie expiry to 1 year #510

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jun 24, 2024

Conversation

anku255
Copy link
Contributor

@anku255 anku255 commented Jun 24, 2024

Summary of change

We decided to update the cookie expiry to 1 year because -

  1. Some browsers cap the max expiry to 400 days. See this for info.
  2. Our docs mention that access token cookie expiry is 1 year.

Test Plan

(Write your test plan here. If you changed any code, please provide us with clear instructions on how you verified your changes work. Bonus points for screenshots and videos!)

Documentation changes

(If relevant, please create a PR in our docs repo, or create a checklist here highlighting the necessary changes)

Checklist for important updates

  • Changelog has been updated
  • coreDriverInterfaceSupported.json file has been updated (if needed)
    • Along with the associated array in supertokens_python/constants.py
  • frontendDriverInterfaceSupported.json file has been updated (if needed)
  • Changes to the version if needed
    • In setup.py
    • In supertokens_python/constants.py
  • Had installed and ran the pre-commit hook
  • Issue this PR against the latest non released version branch.
    • To know which one it is, run find the latest released tag (git tag) in the format vX.Y.Z, and then find the latest branch (git branch --all) whose X.Y is greater than the latest released tag.
    • If no such branch exists, then create one from the latest released branch.
  • If have added a new web framework, update the supertokens_python/utils.py file to include that in the FRAMEWORKS variable
  • If added a new recipe that has a User type with extra info, then be sure to change the User type in supertokens_python/types.py
  • Make sure that syncio / asyncio functions are consistent.
  • If access token structure has changed
    • Modified test in tests/sessions/test_access_token_version.py to account for any new claims that are optional or omitted by the core

@anku255 anku255 force-pushed the fix/access-token-expiry branch from 0f636a8 to 486a239 Compare June 24, 2024 13:32
@rishabhpoddar rishabhpoddar changed the base branch from 0.22 to 0.23 June 24, 2024 13:49
@rishabhpoddar rishabhpoddar merged commit d512c59 into 0.23 Jun 24, 2024
5 of 7 checks passed
@rishabhpoddar rishabhpoddar deleted the fix/access-token-expiry branch June 24, 2024 13:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants