i'm having a diffculty with Access Token. And i'm new in web dev, taking a role in front-end.
So far, my web site is connected with server for log in API, and i can verify user infomation after logged in at console.
However, i'm wondering the way to get access to Access Token which is issued from the server. So, the logic is as follows,
- When i sucess logged in with correct user information, AccessToken and Refresh Tokens are issued.
- I needed a code to access to Access Token, so if i have, i can access to prevented pages (such as, MyPage)
- The Access Token has 30min of expires, so after logged in 30min,the issued Access Token must be expired and lost its access rigth to private pages.
Summary !
- I'm wondering the way to code the AccessToken in Client side to server side after logged in. Found some of informations that saying include Access Token in headers request in Client side.
- How can i code whether the Access Token is expired after 30 min and reqesting again to issue the access-token when i access to private pages with access-token expired state.
- Then, if server can find there is a refresh-token in Client side, then issues access token very easily.
- Wondering should i put all of the pages that check wether AccessToken is alive?
