From 0c64dc68864dc317705443fe6d1876cda6d47d74 Mon Sep 17 00:00:00 2001 From: Federica Agostini Date: Thu, 7 Sep 2023 18:24:05 +0200 Subject: [PATCH] Set exp claim also for 0 AT lifetimes --- .../service/impl/DefaultOAuth2ProviderTokenService.java | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/openid-connect-server/src/main/java/org/mitre/oauth2/service/impl/DefaultOAuth2ProviderTokenService.java b/openid-connect-server/src/main/java/org/mitre/oauth2/service/impl/DefaultOAuth2ProviderTokenService.java index 022f6d77b..1b2735068 100644 --- a/openid-connect-server/src/main/java/org/mitre/oauth2/service/impl/DefaultOAuth2ProviderTokenService.java +++ b/openid-connect-server/src/main/java/org/mitre/oauth2/service/impl/DefaultOAuth2ProviderTokenService.java @@ -220,10 +220,10 @@ public OAuth2AccessTokenEntity createAccessToken(OAuth2Authentication authentica token.setScope(scopeService.toStrings(scopes)); // make it expire if necessary - if (client.getAccessTokenValiditySeconds() != null - && client.getAccessTokenValiditySeconds() > 0) { + if (client.getAccessTokenValiditySeconds() != null ) { Date expiration = new Date(System.currentTimeMillis() + (client.getAccessTokenValiditySeconds() * 1000L)); + token.setExpiration(expiration); }