How to track expired WIF fedauth cookies?

后端 未结 2 557
我在风中等你
我在风中等你 2021-02-09 23:42

I have an interesting problem with trying to keep track of expired WIF authentication sessions/cookies.

As a bit of background: the site is MVC 3, uses Windows Identity

2条回答
  •  闹比i
    闹比i (楼主)
    2021-02-10 00:12

    You don't without keeping a server-side list of the tokens recently revoked. This is why normally we rely upon an inherent expiration as well as HTTPS to prevent the token from being leaked/stolen.

提交回复
热议问题