Replies: 2 comments 4 replies
-
|
Some ideas for future enhancements from @mposolda here: |
Beta Was this translation helpful? Give feedback.
-
|
A suggestion to an alternative to "store LoA in session" and also on how to handle if the cookie is considered level 0, or something else. Add a max_age to a step-up level condition. The identity cookie should allow being used as an alternative of the authenticators for this amount of time. Let's say we have 3 levels:
So basically we consider the identity cookie as long lived if it is older than the max age for the step-up levels. If identity cookie is 30 min old, then it would return level 2. If identity cookie is 120 min old, then it would return level 1, if it's older than 1 day, then it would return 0. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Feedback and questions around step-up authentication
Beta Was this translation helpful? Give feedback.
All reactions