Comment on What information does SJW log from its users? For how long is the respective information kept?

InEnduringGrowStrong@sh.itjust.works ⁨8⁩ ⁨hours⁩ ago

So I’ve just tested something and it seems lemmy devs haven’t set a default expiry time for the login jwt tokens, or it’s something stupidly long.
Logging out clears the cookie from your browser, but not in the server database, which isn’t atypical and mostly fine, or at least would be fine if the server’s expired sooner than later.

Just to be sure, I just tested that a password change does indeed purge those from the database, so that works at least.

I’ll try and see what we can implement locally (hopefully without breaking everything) to purge these more frequently.
Removing these faster also means forcing people to re-enter their credentials more frequently.
I can’t find anywhere to configure that, neither in the instance settings nor in user settings, which probably means it’s whatever lemmy devs set as default.

Anyway, thanks for the question, because it’s dumber than I thought.

source
Sort:hotnewtop