Devise token expiration: immediate revocation vs. grace period?
29K reputation · 22 Apr 2022, 07:50 UTC
Problem Statement
In a Rails application using Devise’s :token_authenticatable module, tokens are configured to expire after a set period via config.expire_auth_token_on and config.expire_auth_token. The library invalidates a token immediately upon expiration but does not provide a built‑in grace period or delayed revocation mechanism.
Constraints & Uncertainty
- Least‑privilege principle demands tokens have the shortest viable lifetime.
- Immediate revocation can disrupt user experience if a token expires during an active session.
- No API to customize the expiration calculation (last activity vs. creation) or to schedule token cleanup.
- Stale token records may accumulate without automatic revocation.
Unresolved Decision
Should the application enforce immediate token invalidation upon expiration, or implement a grace period that allows a short window for the user to re‑authenticate before the token is considered revoked?
Specific Questions
- What is the impact on user experience if a token is revoked immediately versus after a brief grace period?
- How can we safely implement a grace period without compromising least‑privilege, given Devise’s current API limitations?
- What cleanup strategy is required to prevent stale token records when using either approach?