absoluteExpiresAt property
The instant beyond which this session's expiresAt MUST NOT be advanced, by
auth/refresh/0.2 or by any other means — an absolute session lifetime set once at
authentication and never moved forward. Consumers that impose no such ceiling
beyond the session's own rolling expiresAt omit this member; its absence is not
itself a claim that the session is unbounded, only that this response does not
state a bound. See auth/refresh/0.2 Conformance and Security & Privacy for the
enforcement rule.
Implementation
final String? absoluteExpiresAt;