Comment by timewizard
2 days ago
> What are we really checking?
That the security policy for the user and the resulting access key hasn't changed their level of access?
Identity, while the most common use case, is only half the system when federating logins.
Why would you need to reauth for that?
Validated the user that logged in is still the same person.