Closed
Description
In the current implementation of the refresh_token
grant, the access token associated with the old refresh token is revoked
The RFC however makes no mention of this being a requirement, only that the refresh token MAY be revoked which is something that is now configurable.
Metadata
Metadata
Assignees
Labels
No labels