Skip to content

Access protected API with JWT #2067

@geolunalg

Description

@geolunalg

Overview

User Story:
As a user, I want my session to continue seamlessly when my access token expires.

Action Items

Acceptance Criteria:

  • When access token is expired and API returns 401, client calls POST /auth/refresh.
  • Backend reads refresh token from cookie and:
    • if valid: returns a new access token
    • if invalid/expired: returns 401 and client routes to login
  • Client retries the original request once after successful refresh.

Resources/Instructions

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    New Issue Approval

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions