Skip to content

CF UAA Does Not Store or Use External IDP's Refresh Token #3450

@Amitabh36

Description

@Amitabh36

Description:
When integrating with an external Identity Provider (IDP), CF UAA does not store the access token or refresh token issued by the external IDP. This leads to a problem when UAA’s own refresh token expires.

For example, if UAA's refresh token expires in 2 hours but the external IDP's refresh token is valid for 24 hours (or any longer duration depending on its configuration), UAA is unable to obtain a new access token from the external IDP after its own token expires. This is because UAA does not retain the external IDP's refresh token, which would still be valid.

Impact:
This limitation breaks long-lived sessions and forces users to reauthenticate even though the external IDP's refresh token is still valid.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    Inbox

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions