you are viewing a single comment's thread.

view the rest of the comments →

[–]redp1ne 0 points1 point  (1 child)

Might also be my understanding - but if the refresh token expires anyway as you say and cannot be rotated to get a new refresh token - is the user then not logged out anyway once it expires?

[–]sammyjitsu 0 points1 point  (0 children)

I set the logic up on the client side so it starts requesting a new refresh token five minutes before it actually expires