You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Since adding the feature to renew players sessions, if they are active, if a bad actor is able to get a hold of your refresh token now they can indefinitely renew it to always have access to your account.
Proposed solutions:
In case that ever happens, in your profile, have a revoke all sessions button that would invalidate and delete all of your refresh tokens from the database.
Make your session tokens only valid on the original device (user-agent) they are created on. But this would only work if the browser agent is consistent across every request for all machines, which I'm not sure... ?
The text was updated successfully, but these errors were encountered:
I think this needs to wait until a website overhaul, the profile UI could use an upgrade. For example, showing you a list of your recent games, showing you your elo in various variants, showing you your badges and patron status...
Since adding the feature to renew players sessions, if they are active, if a bad actor is able to get a hold of your refresh token now they can indefinitely renew it to always have access to your account.
Proposed solutions:
The text was updated successfully, but these errors were encountered: