Users can currently use the same signature to login. Track if a signature has been used, and enforce expiry