Details
-
Story
-
Status: Closed (View Workflow)
-
P2
-
Resolution: Won't Do
-
None
-
-
CP: R3 2022 roadmap, CP: sprint 125, CP: sprint 126
-
5
-
Core: Platform
-
Lotus R1 2022
Description
Overview
Currently only access tokens issued by the POST /refresh endpoint include an expiration (exp claim). This should be extended to all access tokens issued.
Access token expiration is not currently checked, but should always be.
Acceptance Criteria
- All access tokens should have an expiration
- Authorization should validate that the provided access token has not expired.
TestRail: Results
Attachments
Issue Links
- blocks
-
MODAT-67 One-time use refresh tokens
-
- Closed
-
- is blocked by
-
FOLIO-2556 SPIKE: investigate refresh tokens support in FOLIO
-
- Closed
-
-
MODAT-109 Implement new token types
-
- Closed
-
-
MODAT-110 Implement token persistent store
-
- Closed
-
- is duplicated by
-
MODAT-103 Reject expired auth tokens
-
- Closed
-
- relates to
-
FOLIO-2556 SPIKE: investigate refresh tokens support in FOLIO
-
- Closed
-