In our webapplication the users are signed in using Amplify/Cognito's Auth.federatedSignIn() based on a SAML identity provider.
The related OAuth flow is configured as Authorization code grant.
Is it possible to check whether a user has a "valid" session WITHOUT refreshing the identity- and accesstoken? With valid session I mean that identity- and access-token did not already expire. I have tested these two methods - both are refreshing the tokens (as long as the refresh token is valid):
Auth.currentSession()Auth.currentAuthenticatedUser()
Thanks for your support!