79638427

Date: 2025-05-26 06:46:44
Score: 3
Natty:
Report link

I'm still unable to invalidate the refresh token, even after waiting more than 20 minutes.

The refreshTokensValidFromDateTime field was updated correctly, but I'm still able to use the existing refresh token to obtain a new access token. It seems the refresh token is not being invalidated as expected.

I’ve also checked the portal, and the StsRefreshTokensValidFrom field is correctly set to the current time.

For reference, my token lifetimes are configured as follows:

Is there any known issue that could be causing this?

Reasons:
  • Blacklisted phrase (1): Is there any
  • Long answer (-0.5):
  • Has code block (-0.5):
  • Ends in question mark (2):
  • Low reputation (1):
Posted by: Alpesh