Devise token expiration: immediate revocation vs. grace period?
Problem Statement In a Rails application using Devise’s :token_authenticatable module, tokens are configured to expire after a set period via config.expire_auth_token_on and config.expire_auth_token . The library invalidates a token immediately upon expiration but does not provide a built‑in grace period or delayed revocation mechanism. Constraints & Unc