Skip to content

feat: The Refresh Token Grant flow is supported#206

Draft
mrudatsprint wants to merge 3 commits into
miker/eng-4802/start-logoutfrom
miker/eng-4801/refresh-token
Draft

feat: The Refresh Token Grant flow is supported#206
mrudatsprint wants to merge 3 commits into
miker/eng-4802/start-logoutfrom
miker/eng-4801/refresh-token

Conversation

@mrudatsprint

@mrudatsprint mrudatsprint commented Jul 24, 2026

Copy link
Copy Markdown
Collaborator

Issue:

Description:

Implement the refresh token grant flow. This will include update the tokenStore with new tokens, re-schedule token expiration and auto-refresh.

- refreshToken() branches to a new refreshDpopToken() when useDpop is
  enabled: reads the stored refresh token from DPoPManager, generates a
  DPoP proof for the token endpoint (no ath), POSTs grant_type=refresh_token
  to /oauth2/token with a DPoP header, updates DPoPManager's stored tokens
  on success, and reschedules token expiration / auto-refresh (gated on
  shouldAutoRefresh) from the new expiresAt.
- Throws a descriptive error if no refresh token is stored.
- Cookie-mode refreshToken() behavior is unchanged.
- Adds unit tests covering the DPoP request shape, token update, error
  paths, and expiration/auto-refresh rescheduling.
- Replaces the pre-SDKCore raw refresh-token-grant e2e smoke test with one
  that exercises SDKCore.refreshToken() directly against a live FusionAuth
  instance.
@mrudatsprint
mrudatsprint changed the base branch from main to miker/eng-4802/start-logout July 24, 2026 15:15
@mrudatsprint mrudatsprint changed the title Miker/eng 4801/refresh token feat: The Refresh Token Grant flow is supported Jul 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant