【问题标题】:How JWT token lifetime in Spring boot actually worksSpring Boot 中的 JWT 令牌生命周期实际上是如何工作的
【发布时间】:2017-06-18 03:18:30
【问题描述】:

我已经使用 JWT 令牌实现了 Oauth2.0,直到它似乎基本上可以与 Spring Boot 一起使用。

问题 1:我可以调用此 URL 以获得“access_token”和“refresh_token”作为响应。

https://myapp/oauth/token?grant_type=password&username=______&password=_______

但是当我每次调用 url 时,access_token 和 refresh_token 都重新生成,旧 access_token 仍然可以一直使用,直到它过期。 真的是这样吗? 每次都重新生成?

问题2:此外,当我需要刷新我的access_token时,我调用了这个URL

 https://myapp/oauth/token?grant_type=password&username=______&password=_______

我又获得了两个新的 access_token 和 新的 refresh_token。对我来说,使用 refresh_token 生成更新的 refresh_token 很奇怪。但是旧的 refresh_token 还能用吗?!

如果这已经是 JWT 令牌应该真正起作用的方式,请告诉我为什么我们需要 refresh_token,因为无论如何我们都可以调用第一个 URL 来获取新令牌。

我在这方面花了一些时间,但仍然找不到提及这些事情的明确参考。 如果您能告诉我它应该起作用的正确流程,我将不胜感激。 先感谢您。

【问题讨论】:

标签: spring oauth-2.0 jwt


【解决方案1】:

关于问题 2:是的,你得到了一个新的 access_token 和 refresh_token。 resfresh_token 只能使用一次取决于您(或负责 RefreshTokenProvider 的人)。 这篇博客文章:http://bitoftech.net/2014/07/16/enable-oauth-refresh-tokens-angularjs-app-using-asp-net-web-api-2-owin/(向下滚动到第 6 步)显示了一个示例。

【讨论】:

    猜你喜欢
    • 2020-11-06
    • 2018-12-23
    • 2015-01-08
    • 2021-06-04
    • 2020-01-12
    • 2019-12-01
    • 2021-06-14
    • 2019-06-17
    • 1970-01-01
    相关资源
    最近更新 更多