9974736587681c8bf9881cc0894bbfc8dd232cf1
The client half exists in monorepo-mobile as of f29774a, with OffChat as the proof of concept, so this document is no longer purely forward-looking. Adds a section covering what shipped, the two places the advice here was wrong about the client — one key per app is not possible on mobile (shared-session puts one credential in front of all nineteen apps), and signout was never the problem, distress signout was — and two decisions worth a second opinion: clearing the credential on 401 only, and leaving the traded-in JWT to expire rather than blacklisting it, because that handler clears vault tokens keyed on the user.
Description
No description provided
42 MiB
Languages
TypeScript
90.9%
Shell
4.7%
JavaScript
4.1%
CSS
0.2%
HTML
0.1%