Blazor WebAssembly (WASM) - clear local storage and cookie on browser close

Viewed 398

I have a Blazor WebAssembly project that is a stand-alone SPA and calls API endpoints (with JWT if needed) to perform application functions.

This is how authentication is currently set up in my app: There is a user-validating API that I call when a user tries to sign in. Upon a successful sign-in, the API returns back to me a few pieces of information about the user (e.g., email, name, etc.) and a JWT. I store some of the user information in local storage and the JWT as a cookie.

There is an Authentication State Provider that I have wrapped around my project. The user's auth status is assessed by whether their user information is in the local storage and a cookie exists in the browser. Upon signing out, I clear out the local storage and the JWT cookie.

The issue that I have is this: If a user does not sign out, closes the browser, and opens it back up - they are still authenticated, even though that cookie is technically expired (e.g., after a day) and cannot be used anymore.

I do have an auto-timeout method, which essentially calls a JS function to clear out the local storage and JWT cookie upon 20 minutes or so of inactivity. But this doesn't control for cases where a user simply closes the browser without signing out properly.

--

I'm in dire need of help. Perhaps my authentication setup is entirely wrong, although lot of Blazor WASM tutorials online seem to have their auth system set up this way. I know Blazor Server can have auth set up in a different (perhaps better) way, but what is the best implementation for Blazor WASM?

An idea I had was clearing out the local storage and JWT cookie upon closing the browser. Is there a method for this? I.e., uponBrowserClose()

Or is this just a terrible idea?

0 Answers
Related