Skip to content

Update Refresh Token on proposal API Logic to Expire Only Upon Use #3689

@bosko-m

Description

@bosko-m

Description

Modify the refresh token on proposal API behavior so that it only expires once it has been used or lifespan of token is exceeded.
This ensures better session continuity and avoids premature expiration due to inactivity or background operations.

Acceptance Criteria

  • Refresh token is marked as expired only after it is successfully used to obtain a new access token.
  • Unused refresh tokens remain valid until explicitly used or revoked.
  • Behavior is consistent across login, token refresh, and logout flows.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    To do

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions