Allowing for refresh token rotation during token refresh request - #549
Conversation
|
@sitingren either you can give this a review when you return and I can add tests and we can move forward like that, or if you would prefer I can just hand this off to you in it's current state and you can carry it to the finish line in whatever way you see fit. I'm good with either direction. |
|
I assume there should be an API for client user to get the new refresh token? |
I just added get_current_refresh_token to connection.py. Test: Results: Conclusion: Able to save and use new refresh token |
|
@DMickens Thanks! I'll merge this PR and add more improvements (including update README) in a later PR. |
Modifying 'get_access_token_using_refresh_token' to return both access and refresh tokens, which gets passed through 'do_token_refresh'.
The access token being returned is unchanged. The refresh token being returned is either the same value that is currently saved in the connection in the case that we are not using refresh token rotation. If we are using refresh token rotation, like with OTDS, then we receive a new refresh token every time we use one. This means we have to update what is saved on the connection so that we can get this refresh token programmatically in case we want to do token refresh again.