comparison mod_http_oauth2/README.markdown @ 5617:d8622797e315

mod_http_oauth2: Shorten default token validity periods With refresh tokens, short lifetime for access tokens is not a problem. The arbitrary choice of one hour seems reasonable. RFC 6749 has it as example value. One week for refresh tokens matching the default archive retention period. This means that a client that remains unused for one week will have to sign in again. An actively used client will continually push that forward with each used refresh token.
author Kim Alvefur <zash@zash.se>
date Mon, 24 Jul 2023 01:30:14 +0200
parents 308b5b117379
children f3b7e05c74a9
comparison
equal deleted inserted replaced
5616:59d5fc50f602 5617:d8622797e315
98 98
99 The following options configure the lifetime of tokens issued by the module. 99 The following options configure the lifetime of tokens issued by the module.
100 The defaults are recommended. 100 The defaults are recommended.
101 101
102 ```lua 102 ```lua
103 oauth2_access_token_ttl = 86400 -- 24 hours 103 oauth2_access_token_ttl = 3600 -- one hour
104 oauth2_refresh_token_ttl = nil -- unlimited unless revoked by the user 104 oauth2_refresh_token_ttl = 604800 -- one week
105 ``` 105 ```
106 106
107 ### Dynamic client registration 107 ### Dynamic client registration
108 108
109 To allow users to connect any compatible software, you should enable dynamic 109 To allow users to connect any compatible software, you should enable dynamic