rotateRefreshToken ports OAuthCodeManager::rotateRefresh: a fresh refresh token rotates atomically (revoke old access token, mint successor, link rotated_to_id) while a replayed (already-rotated) token instead revokes the whole lineage and commits that kill before Token maps it to invalid_grant outside the transaction (T-08-REFRESH-REPLAY). Token also runs the D-17 expiry sweep (DeleteExpiredCodes/DeleteExpiredRefreshTokens) before grant processing. Server.Revoke is the new cascade-revoke seam a connected-app controller uses instead of touching refresh rows directly.
14 KiB
14 KiB