229a53fa0a
changes authentication to no longer use a refresh token & access token for accessing protected endpoints. Instead only an auth token is used. Before the login flow was: Login -> get refresh (stored as HttpOnly cookie) + access token (stored in memory) -> protected endpoint request (attach access token as Authorization header) -> access token expires in 15 minutes, so use refresh token to obtain new one when that happens now it looks like this: Login -> get auth token (stored as HttpOnly cookie) -> make protected endpont request (token sent) the reasoning for using the refresh + access token was to reduce DB calls, but in the end I don't think its worth the hassle. |
||
---|---|---|
.. | ||
query | ||
db.go | ||
label_color.sql.go | ||
models.go | ||
notification.sql.go | ||
organization.sql.go | ||
project_label.sql.go | ||
project.sql.go | ||
querier.go | ||
repository.go | ||
system_options.sql.go | ||
task_activity.sql.go | ||
task_assigned.sql.go | ||
task_checklist.sql.go | ||
task_group.sql.go | ||
task_label.sql.go | ||
task.sql.go | ||
team_member.sql.go | ||
team.sql.go | ||
token.sql.go | ||
user_accounts.sql.go |