fix: update refresh token TTL to 30 days #1585
Open
+7
−1
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
fix #1579
In the
generateToken
function, there was logic to set a default 30-day TTL but override it with the options value if present:However, the
defaultOptions
had the refresh token TTL set to just 1 hour:And the service initialization did not explicitly specify the WithRefreshTokenTTL option, so the default 1-hour value was used.
The condition
if s.opts.refreshTokenTTL > 0
was always true, causing the default 30-day setting to always be overridden with the 1-hour value.