Skip to content

fix(oauth): include created_at in token responses - #36

Merged
camreeves merged 1 commit into
masterfrom
fix/token-created-at
Sep 8, 2026
Merged

camreeves merged 1 commit into
masterfrom
fix/token-created-at

Conversation

@camreeves

Copy link
Copy Markdown
Contributor

What

Adds created_at (unix seconds of issuance) to /auth/oauth/token responses, alongside expires_in. Doorkeeper always sent it.

Why

The native Workplace app computes token expiry as created_at + expires_in. With the field absent it reads zero, so every periodic check finds the token expired: refresh, websocket reconnect, full data refetch, repeat. Observed on a placeos-2.2609.1 instance: 39 successful refreshes in ten minutes, 5,666 API requests in one minute, 663 websocket reconnections, then the app starved itself of sockets and froze. The server answered every refresh with 200 throughout.

Tests

The token-exchange spec now asserts created_at is present and within a minute of now.

Doorkeeper's token response carried created_at, and the native Workplace
app computes expiry as created_at + expires_in. Without the field the app
reads zero, treats every token as expired at once, and refreshes and
reconnects in a loop until it runs out of sockets.
@camreeves
camreeves merged commit fb8eb42 into master Sep 8, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants