Laravel SPA with Sanctum and remember me returning 419 (CSRF Token Mismatch) after inactivity

Viewed 338

We are using Laravel Sanctum in a SPA with the "remember_me" option. At this moment we have a session lifetime of 120 seconds.

When a user logs in, Laravel will set 3 cookies;

  • *_session, will expire in 120 seconds
  • XSRF_TOKEN, will expire in 120 seconds
  • remeber_*, will expire in 5 years (forever)

Due to user inactivity, the *_session and XSRF_TOKEN will expire. When the SPA is still open, and the next request will be a POST request, the user will get an 419 response error (CSRF Token Mismatch). Even when the remeber_* cookie is still available.

At this moment we have two options in mind;

  • Ping GET request every 120 seconds.
  • When 419 returned, send a GET request and retry the POST request again.

We are wondering what will be the best solution to fix this?

0 Answers
Related