Rememberable and remember_created_at usefulness

36 views
Skip to first unread message

Filipe Giusti

unread,
May 19, 2016, 5:03:07 PM5/19/16
to Devise
Hi,

I was digging in the source to understand more about the gem I'm depending my project on and I couldn't understand what's the security/ux benefits of the attribute remember_created_at. My understanding is that all that's required to provide the rememberable functionality is already set in the cookie "remember_scope_token", is that right? Could remember_created_at be removed from the code and everything works as expected?

Also to clarify my understanding of devise, does timeoutable provide the same functionality as rememberable with the remember checkbox always checked and extend_remember_period set? If not, what would be the differences?

Thanks.
Reply all
Reply to author
Forward
0 new messages