I have a react app where I am able to login with custom token as follows:
await firebase.auth().signInWithCustomToken(tokenResp.token);
As per this, firebase custom jwt have one hour expiry. And this is what I expect.
But when I make calls to collections that require authentication(i.e. request.auth!=null via firestore rules) after 1 hour, I am able to access them. I would expect the firebase instance to fail(automoatically) after one hour for these calls.
So why is it happening and how do I fix it?
Also note that I have logged in the jwt used to authenticate and clearly the expiry date is one hour by looking at the exp field in jwt decoder.