OIDC access/refresh token changes with OIDC OP v4?

Henri Mikkonen henri.mikkonen at nimbleidm.com
Thu Aug 22 06:12:25 UTC 2024


Hi Keith,

On 22.8.2024 3.55, Wessel, Keith via users wrote:
> We (finally) upgraded to IdP v5 last week, and all went very well aside from some pesky token issues with a mobile app that has long-lived access tokens and extremely long-lived refresh tokens. Same app I've run into issues and talked about here on the list before. We're seeing:
> 
> [net.shibboleth.idp.plugin.oidc.op.userinfo.profile.impl.ParseAccessToken:126] - Profile Action ParseAccessToken: Unable to parse/decode token for validation
> 
> Just before that in the log, we see the IdP successfully retrieving the correct data sealer key version to decode the token. But then it fails to decode.

As the data sealer seems to be correct, then the output above is 
probably caused by the expired access token. The current implementation 
cannot describe the cause why the decoding failed. The plan is to 
improve it though, the following JIRA issue is related:

https://shibboleth.atlassian.net/browse/JOIDC-181

> I know that some new functionality is available in 4.1.0 for custom refreshtoken encoding/decoding, but I assume that left at the defaults, this is unchanged from previous versions.

Indeed, the default configuration should be similar to what you had with 
IdP4/OP3.

> Did anything change between v3 and v4 of the plugin that could have caused our IdP to no longer be able to decode these tokens?

At least not on purpose. We did quite a lot of code cleanup regarding 
handling of null/non-null values, but we have tests that verify that 
even the tokens from OPv2 era should still be compatible.

> Furthermore, some users are reporting that they have to sign back in multiple days in a row. So, it's almost as if the refresh tokens are no longer being honored at all.

One idea: do you set the refresh token timeout via oidc.properties or 
via relying party configuration? Regarding properties, OP4 doesn't wire 
the previously existing property ending with ".defaultLifetime" anymore. 
It was deprecated in OP3.3 and removed in OP4, as mentioned in the 
release notes. The logs warn about it too and hint that you need to use 
'idp.oidc.refreshToken.defaultTimeout' instead.

BR,
Henri.


More information about the users mailing list