TruthLayer/

TruthLayer

local-dev
Back to Conflicts Catalog
High SeverityContradictoryPending Review

Mismatch in Authentication Token Expiration Time

Conflict ID: conflict-token-expiryCreated: 9/12/2026, 2:30:00 PM

Side-by-Side Statement Comparison

JWT Authentication & Security Policy

AuthenticationVer: v3.0.1Updated: 9/10/2026
Document Claim / Excerpt
"JWT authentication tokens expire after 15 minutes of inactivity for maximum protection. Clients must send a refresh token request to obtain a fresh access token before expiration."

User Authentication & Session FAQ

FAQVer: v2.2.0Updated: 7/22/2026
Document Claim / Excerpt
"Session tokens remain valid for 24 hours from issuance unless manually invalidated or logged out by the end user."
AI Analysis

Automated reasoning & conflict explanation

Existing Analysis NoteStage 1 Foundation

Security Policy states JWT tokens expire after 15 minutes of inactivity, but the User Authentication FAQ informs end users that session tokens remain valid for 24 hours. This leads to user session dropouts and security misunderstandings.

AI Analysis Stage Placeholder

AI analysis will be generated in the next stage. Advanced LLM discrepancy reasoning and resolution recommendations will run here.