简体   繁体   中英

Expiration of refresh token in SPA application in AD B2C

Following documentation single-page applications using the authorization code flow with PKCE always have a refresh token lifetime of 24 hours.

I have the same scenario but I wonder if it is possible to set that refresh token expiration time on shorten than 24hours time or event do not use it and force user to type login and password every time access token expires?

Currently its fixed at 24 hours.

You could switch to implicit flow here to achieve this.

The technical post webpages of this site follow the CC BY-SA 4.0 protocol. If you need to reprint, please indicate the site URL or the original address.Any question please contact:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM