-
Notifications
You must be signed in to change notification settings - Fork 11
Open
Description
- What: Add refresh token rotation support when
config.requireTokenRotationis true - Why: Additional security measure - prevents long-term refresh token compromise
- Current State: Configuration option exists but feature not implemented
- Implementation Details:
// In handleRefreshTokenGrant() after generating new access token: if (this.config.requireTokenRotation) { // 1. Generate new refresh token const newRefreshToken = generateRefreshToken(); // 2. Save new refresh token await this.storage.saveRefreshToken(newRefreshToken); // 3. Invalidate old refresh token await this.storage.deleteRefreshToken(refresh_token); // 4. Include in response tokenResponse.refresh_token = newRefreshToken.token; }
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels