Uploaded image for project: 'mod-authtoken'
  1. mod-authtoken
  2. MODAT-67

One-time use refresh tokens

    XMLWordPrintable

Details

    • CP: R3 2022 roadmap
    • 3
    • Core: Platform

    Description

      Overview

      In order to minimize the impact of a leaked refresh token, they should be limited to one-time use.  We should detect when a refresh token is attempted to be used more than once.  When that happens, that refresh token, and all other refresh tokens associated with it should be revoked. 

      Approach

      See the wiki for details

      Acceptance Criteria

      • refresh tokens can only be used once
      • when a refresh token is used more than once, revoke the token and all associated refresh tokens

      TestRail: Results

        Attachments

          Issue Links

            Activity

              People

                Unassigned Unassigned
                cmcnally Craig McNally
                Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:

                  TestRail: Runs

                    TestRail: Cases