Skip to content

use session id when revoking reference tokens for refresh token#1321

Merged
josephdecock merged 1 commit intomainfrom
brock/rt-revocation-include-sid
Jul 7, 2023
Merged

use session id when revoking reference tokens for refresh token#1321
josephdecock merged 1 commit intomainfrom
brock/rt-revocation-include-sid

Conversation

@brockallen
Copy link
Copy Markdown
Member

Fixes: #906

Does add a new param to RemoveReferenceTokensAsync on IReferenceTokenStore, and to the RemoveAllAsync helper on DefaultGrantStore<T>. I don't expect many customers are overriding these classes/methods, but it's possible.

@brockallen brockallen added bug impact/breaking The fix or change will be a breaking one labels Jun 5, 2023
@brockallen brockallen added this to the 7.0 milestone Jun 5, 2023
@brockallen brockallen requested a review from josephdecock June 5, 2023 14:52
@josephdecock josephdecock merged commit 7f4961f into main Jul 7, 2023
@josephdecock josephdecock deleted the brock/rt-revocation-include-sid branch July 7, 2023 16:28
@josephdecock josephdecock mentioned this pull request Nov 13, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

impact/breaking The fix or change will be a breaking one

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Refresh token revocation should filter on sid for reference tokens

2 participants