Just pitching in as someone writing something that might want a
refresh token but *really* doesn't understand why he'd need them. They
make very little sense to me; why not just make the token that allows
you to access a protected resource last longer? Use case: we've got
protected resources that get updated regularly, and authorizations to
read from it are always long-term (generally indefinitely).

Not that my vote carries much weight, but I'm definitely in favor of
simply dropping refresh tokens.

cheers
Laurens
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to