Skip to content

Please improve the documentation around refreshing authorization #140

Description

@giacecco

Perhaps it is me but I can't really understand what you mean in the documentation when you write:

If you provide a refresh_token, in cases when access_token is expired, it asks for a new access_token and replays the request.

it asks... who is "it"? Who needs to replay the request?

I hoped that the conversations around issue #14 and #42 could reveal what was missing, but they don't, and I still don't get how we are supposed to use the refresh_token. Moreover, there are references to a wiki that you probably closed since then.

The example referenced in the documentation also does not cover the refresh scenario.

Thank you in advance for any hint.

Giacecco

Activity

  1. robertrossmann commented on Mar 20, 2014

    @robertrossmann
    Contributor

    I created a pull request with proposed update. I suggest we continue our discussion there if needed.

  2. rakyll commented on Mar 20, 2014

    @rakyll
    Contributor

    Reopening, we need to provide a sample for non-auto access token refreshing.

  3. reopened this on Mar 20, 2014
  4. robertrossmann commented on Mar 20, 2014

    @robertrossmann
    Contributor

    In the absence of the refresh_token the application must do the OAuth flow again; however, this time, there is no user consent screen present and the returned authorisation code can be exchanged for access_token.

    Would it be sufficient to include a similar description on this topic in the README? It seems that the process is mostly the same otherwise.

    Source: OAuth 2.0 for web-server applications

  5. rakyll commented on Mar 20, 2014

    @rakyll
    Contributor

    We presume that the developer is already familiar with OAuth 2.0 flows before using the lib, but it's not the reality at all times.

    We don't need to OAuth 2.0 again, I agree that a link should be sufficient enough.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

🚨This issue needs some love.triage meI really want to be triaged.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions