Class TokenSettings

java.lang.Object
com.codename1.backend.security.oauth2.server.authorization.TokenSettings

public final class TokenSettings extends Object

How long what is issued to one client lasts, in seconds.

Unless set
authorization code 5 minutes
access token 5 minutes
ID token 30 minutes
refresh token 60 minutes from its last use
device code 5 minutes

A refresh token is replaced every time it is used unless isReuseRefreshTokens() says otherwise, and using one that was replaced revokes the whole grant.

  • Method Details

    • builder

      public static TokenSettings.Builder builder()
    • getAuthorizationCodeTimeToLive

      public long getAuthorizationCodeTimeToLive()
    • getAccessTokenTimeToLive

      public long getAccessTokenTimeToLive()
    • getIdTokenTimeToLive

      public long getIdTokenTimeToLive()
    • getRefreshTokenTimeToLive

      public long getRefreshTokenTimeToLive()
    • getDeviceCodeTimeToLive

      public long getDeviceCodeTimeToLive()
    • isReuseRefreshTokens

      public boolean isReuseRefreshTokens()
      Whether a refresh token stays the same when it is used. False unless set: a token that is replaced on every use lets a stolen one be noticed.