I am using laravel sanctum for API authentication for my mobile app.
How can we limit the maximum number of active tokens per user?
Currently, in the personal_access_tokens sanctum generated table, there is no user_id reference. With the current table, imagine if a user logs in and logs out unlimitedly. We will have N number of new tokens created in the table.
- Is there a default way of limiting the total number of tokens per user out of the box or this needs to be done on my own?
- Is this a good practice to have new rows of tokens added to the DB table on every new login?
