Authentication flow using CreateEmailToken() / CreateSession(): empty AccessToken and RefreshToken
- 0
- Self Hosted
- Auth
Hey all,
I am using the .NET SDK for Appwrite v1.7.4 and are working on an authentication / login flow. The process:
- User logs in with mail
- Backend calls Appwrite.CreateEmailToken()
- If ok notify user 3b: servers sents mail, possibly creates user
- User waits for mail to get his secret (OTP, 6 characters)
- Users enters secret
- Backend checks secret with Appwrite.CreateSession() and gets a session
My problem is the general flow ... is off. The session does not provide me with an AccessToken or RefreshToken. Meaning they are empty. It does contain some kind of secret. The earlier generated token also contains a secret I believe.
How do I retrieve the access and refresh tokens? Is the process working differently? Who is handling the token refresh? How long is the token valid? Do I authenticate the user "again" (after he comes back) with the secrets? How do I do that? How long are they valid? ...
Recommended threads
- Can't really use the S3 storage device
hi, I've linked my local MinIO Instance (it's just for testing, not for prod.) to my appwrite instance, when i'm uploading a file it's getting uploaded to the S...
- Next.js SSR Site Times Out on First Visi...
Hey everyone, I'm running a Next.js SSR site on a self-hosted Appwrite server (v1.9.0), and I've noticed a strange behavior that I'm hoping someone can help me...
- Appwrite migration stuck on pending
Migration an existing self hosted 1.9.0 to a new VPS tuning self hosted 1.9.0.. import data recognises the api url, project id and api and then when I create, i...