Hacker News new | ask | show | jobs
by nunez 888 days ago
Interesting. Many of the OAuth services I've used use non-expiring refresh tokens. Though I definitely agree; they should also have an expiry.