I want to limit the number of sessions for user the following way:
- The user can only connect to 4 different devices at a time.
- In order to log in to a 5-th device, the user will have to logout from one of the currently connected devices.
I searched for a SAAS solution, and couldn't find. Searched for NodeJS / Passport libraries, and couldn't find.
Then, I came out with the following idea:
- The DB Unique Key for user would be
JWTToken + Phone Number. - The user will connect using OTP (One-Time-Password) with its phone number.
- I'll save the
JWTToken and the Phone Number. - If the 5-th user wants to sign-in, I'll check whether there are already 5.
- I'll remove the
JWTsession on Logout button click.
So, I have 2 questions in this case:
- Are you familiar with a possible, known solution for my situation (SAAS / Library)?
- Is my solution legitimate? I only see 1 problem - If the user doesn't click on the signout but rather deletes the app / the browser data.
Thank you very much!