OpenConext / OpenConext/OpenConext-oidcng
Rotating refresh token
Open
Nobody has claimed this yet.
not-ready
- Dominant language
- Java
- Stars
- 4
- Forks
- 6
- Avg merge
- 5d 32m
- Merged PRs (30d)
- 3
Description
See https://www.rfc-editor.org/rfc/rfc6749#section-10.4 and the behaviour supported by Okta: https://developer.okta.com/docs/guides/refresh-tokens/main/#refresh-token-rotation
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading RFC 6749 section 10.4 and Okta's refresh-token rotation guide, both linked in the issue. Then locate the gateway's refresh-token flow and determine the expected rotation behavior; the work is done when the gateway supports that behavior consistently.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- authentication
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100