Why do refresh tokens expire after 14 days

让人想犯罪 __ 提交于 2019-11-28 02:46:48

问题


Each refresh token is valid for 14 days. Why do the refresh tokens expire?


回答1:


14 days was based on what is considered best practice in implementing OAuth2. See Why do access tokens expire? for a pretty comprehensive answer about why OAuth2 refresh tokens expire.

We are interested in hearing what number bigger than 14 would work for your application. We picked 14 days based on initial feedback, surveys from application developers, as well as looking at application logins by users. A high majority of users login with apps more often than every 14 days.

Can you explain your use case? What would be the ideal non-infinite refresh-interval that would give you a balance between peace-of-mind about security, and convenience



来源:https://stackoverflow.com/questions/15564486/why-do-refresh-tokens-expire-after-14-days

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!