Skip to main content

"Remember Me" Authentication: Extend session lifetime to reduce OTP login friction

Context & Problem Statement Currently, users are being forced to re-authenticate with an email OTP (One-Time Password) code every 30 minutes. This aggressive session timeout disrupts user workflows, especially when they are spending hours in the platform reviewing policies or uploading evidence. We need to introduce a "Remember Me" function that extends the login session securely, reducing friction while maintaining our baseline security posture.

Acceptance Criteria (AC)

  • Login UI Update: Add a "Remember me on this device" checkbox to the login screen, right below the email input field.

  • Token Architecture (Backend): * If the box is unchecked: Maintain the current behavior (session dies after 30 minutes of inactivity).

    • If the box is checked: Issue a short-lived Access Token (e.g., 30 minutes) AND a secure, HTTP-only, long-lived Refresh Token (e.g., 7 days).

  • Silent Refresh: Implement logic in the frontend to intercept 401 Unauthorized errors, silently use the Refresh Token to get a new Access Token in the background, and retry the failed request without interrupting the user.

  • Explicit Logout: If a user clicks "Log Out", the backend must immediately revoke and blacklist both the Access Token and the Refresh Token for that device.

Log in to comment and vote

No comments yet

Be the first to share your thoughts.