Hacker News new | ask | show | jobs
by bobbylarrybobby 1299 days ago
My impression was that the device was repeatedly fetching site.com/auth/userid/session_id and waiting for a response with a token in it.
2 comments

Yes, the RFC is quite readable and this is mentioned in the intro.

https://www.rfc-editor.org/rfc/rfc8628

This is correct.