You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Problem: how do we distinguish between a device expiry and a token expiry?
If we don't, we'll end up keeping device-scoped data forever, in particular, to-device messages. This will be A Problem.
I mooted that
Maybe it's sufficient to look for soft or hard logouts, and expire entire devices on hard logouts?
But for this we'd have to understand how the OIDC "compatability" layer works in Synapse. Do device expiries get communicated as hard logouts, and do token expiries get communicated as soft logouts? I will need to understand what is going on and liase with @sandhose.
The text was updated successfully, but these errors were encountered:
As noticed here #51 (comment)
I mooted that
But for this we'd have to understand how the OIDC "compatability" layer works in Synapse. Do device expiries get communicated as hard logouts, and do token expiries get communicated as soft logouts? I will need to understand what is going on and liase with @sandhose.
The text was updated successfully, but these errors were encountered: