Skip to content
Discussion options

You must be logged in to vote

Hello @Wilmast
Many apologies for the late answer!

This is not easy to pull off if you are using an OAuth2.0 based flow.
It does not make sense to revoke the refresh token to invalidate a session.
I recommend taking a look at these documents:
Access and Refresh Tokens are not Sessions!
A bit more controversial but worth a read:
Why you probably do not need OAuth2 / OpenID Connect

Replies: 2 comments 4 replies

Comment options

You must be logged in to vote
2 replies
@pflipp
Comment options

@vinckr
Comment options

Answer selected by vinckr
Comment options

You must be logged in to vote
2 replies
@vinckr
Comment options

@pflipp
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants