spring-security icon indicating copy to clipboard operation
spring-security copied to clipboard

Ensure ID Token is updated after refresh token (Reactive)

Open evgeniycheban opened this issue 7 months ago • 3 comments

Closes gh-17188

evgeniycheban avatar Jun 14 '25 13:06 evgeniycheban

Thanks for your patience @evgeniycheban and apologies that I could not get this into 7.0. We had quite a workload for this round of majors.

I have scheduled this for 7.1.0-M1 and will review this soon. In the meantime, when you have a moment can you please rebase. Thank you.

jgrandja avatar Nov 12 '25 11:11 jgrandja

Hi @jgrandja, I have rebased my branch and also updated license headers to meet new pattern, let me know your feedback once you review it, thanks.

evgeniycheban avatar Nov 18 '25 22:11 evgeniycheban

@evgeniycheban I took a look at the PR and noticed that the implementation is different compared to the Servlet implementation.

RefreshTokenReactiveOAuth2AuthorizationSuccessHandler combines the logic in OidcAuthorizedClientRefreshedEventListener and OidcUserRefreshedEventListener and does not make use of Spring Framework's ApplicationEventPublisher and ApplicationListener.

The preference is to keep the Servlet and Reactive implementations as close as possible. Is there a reason you did not make use of ApplicationEventPublisher and ApplicationListener ?

Just a heads up that I'm on PTO starting tomorrow and returning Jan 5 so I'll reply when I return and we can work through this.

jgrandja avatar Dec 11 '25 20:12 jgrandja