jamesfredley commented on issue #15901:
URL: https://github.com/apache/grails-core/issues/15901#issuecomment-5972518964

   The refresh token is returned on the first access-token response. With JWT 
and `grails.plugin.springsecurity.rest.token.validation.useBearerToken` left at 
its default of `true`, `DefaultAccessTokenJsonRenderer` adds `refresh_token` 
whenever the generated access token has one. That renderer is on `8.0.x`, 
`8.1.x`, and `9.0.x`.
   
   The REST guide shows that JSON response under "Token expiration and refresh 
tokens", and the following request posts that value to `/oauth/access_token` as 
`grant_type=refresh_token`:
   
   https://grails.apache.org/docs/latest/guide/single.html
   
   `RestOauthController` only accepts that refresh grant. It does not create 
the original refresh token. Store the `refresh_token` field from the first 
login response.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to