You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This effectively means we cannot revoke an access token if using refresh tokens, since it makes the refresh token useless.
Describe your ideal solution
Ideally, we'd like the token revocation endpoint to not revoke refresh tokens when an access token is revoked.
Alternatively, it would work if we could to configure this behavior (either globally for our hydra instance or with an additional parameter to the revocation endpoint).
Workarounds or alternatives
We're not revoking access tokens where we'd like to be right now.
Another alternative would be to expose an admin endpoint in ory/hydra to revoke just access tokens.
Version
oryd/hydra:v2.1.1
Additional Context
No response
The text was updated successfully, but these errors were encountered:
Preflight checklist
Describe your problem
We'd like to be able to revoke an individual access token without revoking a refresh token.
The spec says:
Currently, fosite revokes both access and refresh tokens on any token revocation:
fosite/handler/oauth2/revocation.go
Lines 58 to 59 in 45a6785
This effectively means we cannot revoke an access token if using refresh tokens, since it makes the refresh token useless.
Describe your ideal solution
Ideally, we'd like the token revocation endpoint to not revoke refresh tokens when an access token is revoked.
Alternatively, it would work if we could to configure this behavior (either globally for our hydra instance or with an additional parameter to the revocation endpoint).
Workarounds or alternatives
We're not revoking access tokens where we'd like to be right now.
Another alternative would be to expose an admin endpoint in ory/hydra to revoke just access tokens.
Version
oryd/hydra:v2.1.1
Additional Context
No response
The text was updated successfully, but these errors were encountered: