Skip to content

Conversation

@markstos
Copy link
Contributor

See commit message for more detail.

The changed behavior of accessTokenLifetime is a undocumented breaking
change in 3.0.

The old behavior was spec-compliant and explicitly documented as an
advertised fature in the CHANGELOG entry for 1.5.0, so a "Breaking Change"
notice is warranted.

The spec is clear that the expiration date is *recommended*, not required.

Ref: https://tools.ietf.org/html/rfc6749#section-5.1
@thomseddon thomseddon changed the base branch from dev to master August 3, 2018 09:27
@thomseddon
Copy link
Member

Thanks 👍

@thomseddon thomseddon merged commit 4090055 into oauthjs:master Aug 3, 2018
mjsalinger pushed a commit to mjsalinger/node-oauth2-server that referenced this pull request Aug 27, 2018
…-for-expiration-times

Add missing notice of breaking change for accessExpireLifetime to migration guide.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants