Hacker News new | ask | show | jobs
by jbri 4734 days ago
How do you tell if the user's session has expired so you know to ask them to re-authenticate before doing anything sensitive?
1 comments

AFAIK the re-authentication thing has nothing to do with expiring sessions. The whole point is to ask users to re-authenticate even though their sessions are still alive and well. Enter your password again to change your privacy settings, etc.