Do not invalidate the previous refresh token after refresh #7390
Unanswered
dblock
asked this question in
API Feature Requests & Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
A call to
oauth2/token
withgrant_type: refresh_token
will invalidate the previous refresh token. If the newly obtained token cannot be saved (say because of an intermittent infrastructure problem) there's no longer a way to obtain a refreshed Bearer token for the caller. The only way is to re-authorize that involves the user.It should be possible to obtain a new refresh token with any (or at least some) prior valid refresh tokens.
Beta Was this translation helpful? Give feedback.
All reactions