The HttpClient handler that injects tokens has a hardcoded refresh buffer of 5 minutes for attempting a refresh
- Dominant language
- C#
- Stars
- 38.4k
- Forks
- 10.9k
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 276
Description
Originally posted by @ascott18:
https://github.com/dotnet/aspnetcore/issues/40764#issuecomment-1781629719
> The HttpClient handler that injects tokens has a hardcoded refresh buffer of [5 minutes](https://github.com/dotnet/aspnetcore/blob/ffa0a028464e13d46aaec0c5ad8de0725a4d5aa5/src/Components/WebAssembly/WebAssembly.Authentication/src/Services/AuthorizationMessageHandler.cs#L59) for attempting a refresh, but AuthenticationService.ts will continue serving the token from the javascript side until it is fully expired (effectively a hardcoded refresh buffer of zero seconds). A buffer of 5 minutes causes problems if your server issues 5-minute access tokens, though, which is the lowest possible access token duration for many services (Okta/Auth0, AWS Cognito, and probably many others)
Contributor guide
Assessment
This issue has not been assessed yet.