Skip to content

[Feature] Make the "Remember me" checkbox on sign-in actually do something - #1549

Closed
gabrielfalcao wants to merge 1 commit into
worknenjoy:masterfrom
gabrielfalcao:remind-me-do-something
Closed

gabrielfalcao wants to merge 1 commit into
worknenjoy:masterfrom
gabrielfalcao:remind-me-do-something

Conversation

@gabrielfalcao

@gabrielfalcao gabrielfalcao commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

pass state around so that "remember me" can be sent to the backend API when and where that seems reasonable to do so

closes #1547

…I when and where that seems reasonable to do so
@alexanmtz

Copy link
Copy Markdown
Member

@gabrielfalcao check the backend proposal.

💡 Proposed Solution

  1. Backend — accept a "remember" flag from the login request and vary the JWT's lifetime accordingly:
    • Add passReqToCallback: true to the local Passport strategy config so the verify callback can read req.body.remember.
    • Sign the JWT with jwt.sign(payload, secret, { expiresIn }), where expiresIn is short when remember is falsy (e.g. 1d) and long when truthy (e.g. 30d). Exact durations are open to discussion/maintainer input.
    • Confirm token verification (src/app/routes/secure.ts, src/utils/auth/authenticationHelpers.ts, both using jwt.verify) correctly surfaces an expired-token error as a 401 once tokens actually carry an exp claim (they currently never hit this path since no token expires).

@alexanmtz alexanmtz closed this Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature] Make the "Remember me" checkbox on sign-in actually do something

2 participants