I am using the lastest .NET 5 Blazor Web Assembly Core Hosted template available in Visual Studio 2019. It already has support for authentication out of the box.
The issue is that I can expire the Cookie on the .NET Hosted (server) side like this in Startup.cs in the method ConfigureServices(IServiceCollection services):
services.ConfigureApplicationCookie(options =>
{
options.AccessDeniedPath = "/Identity/Account/AccessDenied";
options.Cookie.Name = "MyCookie";
options.Cookie.HttpOnly = true;
options.ExpireTimeSpan = TimeSpan.FromMinutes(20);
options.LoginPath = "/Identity/Account/Login";
options.ReturnUrlParameter = CookieAuthenticationDefaults.ReturnUrlParameter;
options.SlidingExpiration = true;
});
However, my requirement is that when the session expires after 20 minutes, the user should be asked to login again. My problem with this is that the cookie only expires if the browser is closed or the user hits reload. In the meantime, I can hit all the controllers even if they have the [Authorize] tag in them. The ideal situation is when the user calls a controllers then it redirects to login.
Cookies are created after login.
When time has passed cookies are gone, but the user still has all permissions.