Skip to content

Handle loosing track of Refresh Token #272

Answered by vinckr
MollardMichael asked this question in Q&A
Discussion options

You must be logged in to vote

Hello @MollardMichael
I think this problem is built into the whole access/refresh token mechanism.
The solution is to not use an OAuth2 mechanism for authentication.

Learn more about the Ory Identities security model here: https://www.ory.sh/docs/security-model
Blogpost on the limitations of OAuth2: https://www.ory.sh/oauth2-openid-connect-do-you-need-use-cases-examples/

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by vinckr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants