Authentication flow using CreateEmailToken() / CreateSession(): empty AccessToken and RefreshToken
- 0
- Self Hosted
- Auth
Hey all,
I am using the .NET SDK for Appwrite v1.7.4 and are working on an authentication / login flow. The process:
- User logs in with mail
- Backend calls Appwrite.CreateEmailToken()
- If ok notify user 3b: servers sents mail, possibly creates user
- User waits for mail to get his secret (OTP, 6 characters)
- Users enters secret
- Backend checks secret with Appwrite.CreateSession() and gets a session
My problem is the general flow ... is off. The session does not provide me with an AccessToken or RefreshToken. Meaning they are empty. It does contain some kind of secret. The earlier generated token also contains a secret I believe.
How do I retrieve the access and refresh tokens? Is the process working differently? Who is handling the token refresh? How long is the token valid? Do I authenticate the user "again" (after he comes back) with the secrets? How do I do that? How long are they valid? ...
Recommended threads
- Appwrite-injected variables are not avai...
I am using rust-1.83 as a runtime and try to access APPWRITE_FUNCTION_API_ENDPOINT or APPWRITE_FUNCTION_API_KEY during runtime. Both are not set during my execu...
- OAuth Missing redirect URL
Hello all, on a Flutter mobile app with latest Appwrite dependency (25.4.0) I always got "Missing redirect URL" - "Your OAuth login flow is missing a proper red...
- Custom domain for Google Auth
Hello! I connected my custom domain to my Appwrite project, but I can't get the Google login/consent screen to show my domain instead of the Appwrite domain. I...