Mercurial > prosody-modules
annotate .hgtags @ 5617:d8622797e315
mod_http_oauth2: Shorten default token validity periods
With refresh tokens, short lifetime for access tokens is not a problem.
The arbitrary choice of one hour seems reasonable. RFC 6749 has it as
example value.
One week for refresh tokens matching the default archive retention
period. This means that a client that remains unused for one week will
have to sign in again. An actively used client will continually push
that forward with each used refresh token.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Mon, 24 Jul 2023 01:30:14 +0200 |
parents | 9fa588babbba |
children |
rev | line source |
---|---|
638
60cee6923ee7
Tagging last 0.8.x compatible revision of this repo, for 0.8.x support move to http://code.google.com/p/prosody-modules.0-8/
Matthew Wild <mwild1@gmail.com>
parents:
diff
changeset
|
1 2c07bcf56a36d6e74dc0f5422e89bd61f4d31239 0.8-diverge |
2169
9fa588babbba
Tag last commit available on Google Code for future reference
Kim Alvefur <zash@zash.se>
parents:
638
diff
changeset
|
2 1656d4fd71d07aa3a52da89d4daf7723a555e7dd last-google-code-commit |