Skip to content

Commit 7136ee9

Browse files
committed
fix: rotate refresh token
1 parent fd9eb7c commit 7136ee9

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

server/handlers/token.go

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -143,6 +143,8 @@ func TokenHandler() gin.HandlerFunc {
143143
userID = claims["sub"].(string)
144144
roles = claims["roles"].([]string)
145145
scope = claims["scope"].([]string)
146+
// remove older refresh token and rotate it for security
147+
sessionstore.RemoveState(refreshToken)
146148
}
147149

148150
user, err := db.Provider.GetUserByID(userID)

0 commit comments

Comments
 (0)