3 ms·
> invalidating refresh keys after single use That's called refresh token rotation and is a valid security practice.
by theonething 1y ago
> invalidating refresh keys after single use
That's called refresh token rotation and is a valid security practice.
- another_twist 1y agoI know but the RFC doesnt mandate it. https://datatracker.ietf.org/doc/html/rfc6749#section-6 https://datatracker.ietf.org/doc/html/rfc6749#section-6 Not sure why Google doesnt do this but Atlassian does.
- cropcirclbureau 1y agoGoogle OAuth2 refresh tokens are definitely singe use.
- another_twist 1y agoAtleast not documented here https://developers.google.com/identity/protocols/oauth2#5.-refresh-the-access-token,-if-necessary https://developers.google.com/identity/protocols/oauth2#5.-r.... They have a limit on the number of tokens but not on number of uses per token.