backend requirements onthe xustomer app
This commit is contained in:
@@ -80,7 +80,18 @@ type Claims struct {
|
||||
}
|
||||
|
||||
func GenerateToken(userID int, email string, roleID int, tenantID int, configID int, secret string) (string, error) {
|
||||
expirationTime := time.Now().Add(24 * time.Hour)
|
||||
return GenerateTokenWithTTL(userID, email, roleID, tenantID, configID, secret, 24*time.Hour)
|
||||
}
|
||||
|
||||
// GenerateTokenWithTTL is GenerateToken with an explicit lifetime.
|
||||
//
|
||||
// The customer app pairs a short access token with a long-lived refresh token,
|
||||
// so a stolen access token expires in an hour rather than a day, while the
|
||||
// customer still stays signed in for months. The miler and console surfaces
|
||||
// keep the 24-hour default: they have no refresh endpoint, and shortening their
|
||||
// token would sign a rider out mid-shift.
|
||||
func GenerateTokenWithTTL(userID int, email string, roleID int, tenantID int, configID int, secret string, ttl time.Duration) (string, error) {
|
||||
expirationTime := time.Now().Add(ttl)
|
||||
claims := &Claims{
|
||||
UserID: userID,
|
||||
Email: email,
|
||||
|
||||
Reference in New Issue
Block a user