Skip to content

Comments

added check access token validity before refresh#309

Open
fbarresi wants to merge 1 commit intoDuendeSoftware:mainfrom
fbarresi:main
Open

added check access token validity before refresh#309
fbarresi wants to merge 1 commit intoDuendeSoftware:mainfrom
fbarresi:main

Conversation

@fbarresi
Copy link

I use a RefreshTokenDelegatingHandler to gather a bearer token from a refresh token in my application.
However, I noticed in my code that reusing the handler (rather than instantiating it again) leads to error replies due to the use of an expired token.

This seems to be because the validity of the token after a refresh is never evaluated in successive usages, and the RefreshTokenDelegatingHandler attempts to use the expired token anyway.

In general, I think evaluating token expiration (when known) should be a common function of this handler. Additionally, reusing the handler instead of recreating it would minimise the number of requests to the IDP.

@fbarresi fbarresi marked this pull request as draft January 14, 2026 15:42
@fbarresi fbarresi marked this pull request as ready for review January 14, 2026 15:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant