jamesfredley commented on issue #15901: URL: https://github.com/apache/grails-core/issues/15901#issuecomment-5972518964
The refresh token is returned on the first access-token response. With JWT and `grails.plugin.springsecurity.rest.token.validation.useBearerToken` left at its default of `true`, `DefaultAccessTokenJsonRenderer` adds `refresh_token` whenever the generated access token has one. That renderer is on `8.0.x`, `8.1.x`, and `9.0.x`. The REST guide shows that JSON response under "Token expiration and refresh tokens", and the following request posts that value to `/oauth/access_token` as `grant_type=refresh_token`: https://grails.apache.org/docs/latest/guide/single.html `RestOauthController` only accepts that refresh grant. It does not create the original refresh token. Store the `refresh_token` field from the first login response. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
