Skip to content

Plan refresh token strategy for MVP auth #21

Description

@sardorcodev

Plan a future refresh-token strategy for Smart Agro AI authentication.

Current status:

  • JWT access tokens exist.
  • No refresh tokens are implemented.
  • localStorage token storage is MVP-only.

Scope:

  • Document possible refresh-token architecture.
  • Identify security tradeoffs.
  • Do not implement until design is approved.

Acceptance criteria:

  • SECURITY_NOTES.md or a design doc includes refresh-token options.
  • Risks are documented.
  • Implementation is split into future issues.

Metadata

Metadata

Assignees

No one assigned

    Labels

    backendFastAPI/backend workenhancementNew feature or requestsecurityAuth, secrets, CORS, JWT, rate limit

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions