Replies: 1 comment
-
see also: |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
From Google Identity documentation:
Currently, assuming a refresh token grace period is not set, to break an account link it is enough to run the Google Smart Home Test Suite, specifically the refresh token test triggers token reuse detection, which invalidates the only refresh token. After that, it is only possible for Google to acquire another refresh token once the user does the grant flow once again.
While the grace period does prevent the above breakeage scenario the core issue seems to be the single point of failure, so Google's recommendation seems to make sense.
Now comes the question: was the single refresh token a design decison from the team? Or is multiple refresh token handling simply something which happens to not be implemented yet but which would be accepted mainstream once done?
Beta Was this translation helpful? Give feedback.
All reactions