Handling short inactivity timeout and user acceptance of repeated session expiration

I was able to find out from our team @schmaga that we are currently working on solutions to securely support refresh tokens in SPAs. We expect to be able to share more details in the near future!