and more in a single search tool across platforms. Read the announcement here. |
02/28/2024 05:21 PM
We have a customer who would like the refreshToken generated to expire after every use, as specified in the latest Security Best Current Practice.
Is this achievable in Saviynt using the available configuration process?
Solved! Go to Solution.
02/28/2024 07:00 PM
This is accepted as enhancement
https://ideas.saviynt.com/ideas/EIC-I-4932
02/29/2024 02:27 AM - edited 02/29/2024 02:28 AM
HI @flegare , It is supported but we/clients don't have access to make changes to the configurations.
We raised a ticket with Saviynt to get it updated.
Note: If grails.plugin.springsecurity.rest.refreshtoken.storage.jwt.expiration is set to some value in Config.groovy, refresh token will expire based on this config in api/login api. This will generate a new refresh token if another config - grails.plugin.springsecurity.rest.refreshtoken.new is set to true in Config.groovy. For blank or null, it will return the same Refresh token as passed in oauth/access_token api
Thanks ,
Amit
If this answers your query, Please ACCEPT SOLUTION and give KUDOS.
02/29/2024 05:28 AM
Hi @AmitM ,
This Config.groovy has nothing do to with the AuthenticationConfig.groovy file that we can maintain ourselves then, is it correct?
02/29/2024 05:31 AM
Correct both are different.
Thanks,
Amit
02/29/2024 05:40 AM
If one was prone to sarcasm outbursts, one would ask why they feel the need to document this bit of information in the public api reference.
Thankfully, I am not that kind of individual. Would go nuts real quick otherwise.
Thanks for the quick reply, much, much appreciated!