diff --git a/apps/docs/pages/guides/auth/server-side-rendering.mdx b/apps/docs/pages/guides/auth/server-side-rendering.mdx index dc39ab61296..64b04fdd93d 100644 --- a/apps/docs/pages/guides/auth/server-side-rendering.mdx +++ b/apps/docs/pages/guides/auth/server-side-rendering.mdx @@ -71,7 +71,7 @@ It introduces a few additional steps which guard a against replay and URL captur >
Implicit} + header={Implicit} id={`ssr-implicit-flow`} > @@ -103,17 +103,17 @@ approach also avoids leaking credentials in request or access logs. If you wish
PKCE} + header={PKCE} id={`ssr-pkce-flow`} > When using the PKCE flow, a redirect URL will be returned with the following structure: ``` https://yourapp.com/...?code=<...> ``` - The `code` parameter is commonly known as the Auth Code. The Auth Code can then be exchanged for an access token by calling `exchangeCodeForSession(code)` method. + The `code` parameter is commonly known as the Auth Code and can be exchanged for an access token by calling `exchangeCodeForSession(code)`. For security purposes, the code has a validity of 5 minutes and can only be exchanged for an access token once. You - will need to initiate the authentication flow again if you wish to obtain a new access token. + will need to restart the authentication flow from scratch if you wish to obtain a new access token. As the flow is run server side, `localStorage` may not be available. You may configure the client library to use a custom storage adapter an alternate backing storage such as cookies