Comment by wrs
3 months ago
The RefreshAt is a week, but if the code is actually valid for a week, it's not clear why a simple screenshot of the code didn't work.
3 months ago
The RefreshAt is a week, but if the code is actually valid for a week, it's not clear why a simple screenshot of the code didn't work.
It seems like it did work and they didn't want to deal with manually updating it weekly
I don't know security that well but if the puregym app refreshes the token then the old tokens would expire immediately right?
Nope. As I read it, any token less than a week old would work. So for any user, they have 7 * 24 * 60 tokens live at any time.
He said the code from Monday didn't work on Tuesday
2 replies →
no
Because you’d have to waste the time to take a new screenshot every week, of course.
Probably invalidates old tokens when a new one is generated.