KemalIdentity::Sessions::RememberToken
One link in a remember-me chain.
Every token descended from a single login shares a family_id. Presenting a token spends
it and mints its successor in the same family, so at any moment exactly one token per
family is live and the rest are spent history.
That history is the point. It is what turns theft from something nobody notices into something the next request detects.
Constructors
Instance methods
account_id
Sourcecreated_at
Sourceexpires_at
Sourcefamily_id
Shared by every token rotated from one original login. Revoking a family ends that browser's remembered state and leaves every other device alone.
id
Sourcerevoked?
Sourcerevoked_at
Killed, rather than spent. Distinct from used_at because the difference is exactly what
an audit trail needs to tell "this rotated" from "we believe this was stolen".
token_digest
Sourceused?
Source