Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.

public final class TokenSettings

  1. Object
  2. TokenSettings

How long what is issued to one client lasts, in seconds.

Unless set
authorization code5 minutes
access token5 minutes
ID token30 minutes
refresh token60 minutes from its last use
device code5 minutes

A refresh token is replaced every time it is used unless isReuseRefreshTokens says otherwise, and using one that was replaced revokes the whole grant.

Nested types

class TokenSettings.BuilderBuilds a TokenSettings.

Methods

public static TokenSettings.Builder builder()
public long getAuthorizationCodeTimeToLive()
public long getAccessTokenTimeToLive()
public long getIdTokenTimeToLive()
public long getRefreshTokenTimeToLive()
public long getDeviceCodeTimeToLive()
public boolean isReuseRefreshTokens()Whether a refresh token stays the same when it is used.

Inherited methods

Method details

builder

public static TokenSettings.Builder builder()

getAuthorizationCodeTimeToLive

public long getAuthorizationCodeTimeToLive()

getAccessTokenTimeToLive

public long getAccessTokenTimeToLive()

getIdTokenTimeToLive

public long getIdTokenTimeToLive()

getRefreshTokenTimeToLive

public long getRefreshTokenTimeToLive()

getDeviceCodeTimeToLive

public long getDeviceCodeTimeToLive()

isReuseRefreshTokens

public boolean isReuseRefreshTokens()
Whether a refresh token stays the same when it is used. False unless set: a token that is replaced on every use lets a stolen one be noticed.