leemurus
01/25/2024, 3:10 PM/recipe/session/verify
handler just approve and write new refresh token to database? Before this action new refresh token is not valid?
3. Do you have any heuristic algorithm for detecting theft?
4. You have really small article about csrf tokens. Do you have big article with more detailed description about it?
https://supertokens.com/docs/thirdparty/common-customizations/sessions/anti-csrfrp_st
01/26/2024, 6:18 AM