Refreshing cookie ticket in ASP.NET Core MVC

Viewed 626

I'm using .NET Core and OpenID Connect, with cookie configured with SlidingExpiration = true and ExpireTimeSpan = 20 minutes.

What I observe is that while I am working on task in the application and not knowing the cookie's ticket has expire due to the ExpireTimeSpan. The application will not execute any function example: prompting me that time is about the expire or log me out.

What I understand so far is that SlidingExpiration should provide me with a new ticket if they refresh the page 10 mints or so, but what I notice it is otherwise.

So I wonder is there anyway I can get the cookie's ticket renew before the expire and the task/process should be transparent to me. What I notice in CookieAuthenticationHandler.cs there is a cool function call OnCheckSlidingExpiration. I am wondering how should I use that function in my current application.

2 Answers

According to the source codes, I found the OnCheckSlidingExpiration method is called by the CookieAuthenticationHandler's CheckForRefreshAsync method.

The source codes of the CheckForRefreshAsync method is like below:

    private async Task CheckForRefreshAsync(AuthenticationTicket ticket)
    {
        var currentUtc = Clock.UtcNow;
        var issuedUtc = ticket.Properties.IssuedUtc;
        var expiresUtc = ticket.Properties.ExpiresUtc;
        var allowRefresh = ticket.Properties.AllowRefresh ?? true;
        if (issuedUtc != null && expiresUtc != null && Options.SlidingExpiration && allowRefresh)
        {
            var timeElapsed = currentUtc.Subtract(issuedUtc.Value);
            var timeRemaining = expiresUtc.Value.Subtract(currentUtc);

            var eventContext = new CookieSlidingExpirationContext(Context, Scheme, Options, ticket, timeElapsed, timeRemaining)
            {
                ShouldRenew = timeRemaining < timeElapsed,
            };
            await Options.Events.OnCheckSlidingExpiration(eventContext);

            if (eventContext.ShouldRenew)
            {
                RequestRefresh(ticket);
            }
        }
    }

If you want to write your own logic for refresh cookie token, I suggest you could try to rewrite this hanlder.

More details about how to rewrite this method, you could refer to this article.

It's been awhile and I forget to reply my answer.

I've solve my issue using ajax script:

  1. set an interval of x number of seconds before the cookie expire and once the the time is up, call the function.
  2. the function shall open another small window(to do the refresh) and then close the small window
  3. The cookies has refreshed!

Example of the ajax script: setInterval(function () { redirectRefreshSessionPage(); }, 900000); //set interval as every 15mins

    function redirectRefreshSessionPage() {
    $.ajax({
        url: "{uri for refresh window}",
        method: "GET",
        dataType: "html"
    })
        .done(
            function (data) {
                let options = { focus: false, keyboard: true };
                $("#sessionModalWrapper").html(data);
                $('#refresh page modal').modal(options);
                $('#refresh page modal').modal('show');
            }
        );
    }
</script>
Related