We are using Laravel Sanctum in a SPA with the "remember_me" option.
At this moment we have a session lifetime of 120 seconds.
When a user logs in, Laravel will set 3 cookies;
*_session, will expire in 120 secondsXSRF_TOKEN, will expire in 120 secondsremeber_*, will expire in 5 years (forever)
Due to user inactivity, the *_session and XSRF_TOKEN will expire. When the SPA is still open, and the next request will be a POST request, the user will get an 419 response error (CSRF Token Mismatch). Even when the remeber_* cookie is still available.
At this moment we have two options in mind;
- Ping
GETrequest every 120 seconds. - When 419 returned, send a
GETrequest and retry thePOSTrequest again.
We are wondering what will be the best solution to fix this?