You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于使用Asgardeo Tomcat库刷新过期AccessToken及调用中使用PKCE扩展的技术问询

Hey there, let’s break down your two questions about the Asgardeo library for Tomcat clearly:

1. Refreshing an Expired Access Token

The Asgardeo Tomcat library supports using refresh tokens to get a new access token without forcing the user to re-login—here’s how to implement it:

  • First, ensure your initial authentication flow includes the offline_access scope. This is required to receive a refresh_token alongside your initial access_token (most client configurations have this enabled by default, but double-check your Asgardeo client settings if you’re not seeing a refresh token).
  • When your access token expires, use the stored refresh token to trigger a token refresh. Here’s a simplified code example:
// Initialize your existing Asgardeo auth client (you likely have this set up already)
AsgardeoAuthClient authClient = new AsgardeoAuthClient.Builder()
        .clientId("your-client-id")
        .clientSecret("your-client-secret")
        .tokenEndpoint("https://<your-asgardeo-tenant>/oauth2/token")
        .build();

// Build the refresh request with your stored refresh token
TokenRefreshRequest refreshRequest = new TokenRefreshRequest.Builder()
        .refreshToken("your-stored-refresh-token")
        .build();

// Fetch the new token set
TokenResponse tokenResponse = authClient.refreshToken(refreshRequest);

// Update your stored tokens: note that some flows issue a new refresh token too
String newAccessToken = tokenResponse.getAccessToken();
String newRefreshToken = tokenResponse.getRefreshToken();
  • Pro tip: Always store refresh tokens securely (e.g., in a server-side session or encrypted storage) since they grant long-term access to your application.
2. Using the PKCE Extension

Yes, the Asgardeo Tomcat library fully supports PKCE (Proof Key for Code Exchange)—this is especially critical for public clients (like Tomcat apps that can’t safely store a client secret). Here’s how to use it:

  1. Enable PKCE in your Asgardeo client: In the Asgardeo console, go to your client’s settings and set "PKCE Mandatory" to Yes (or leave it as Optional if you want to support both flows).
  2. Generate a code verifier and challenge before initiating the authorization request:
// Use the library's built-in PKCE utilities to generate secure values
String codeVerifier = PKCEUtils.generateCodeVerifier();
String codeChallenge = PKCEUtils.generateCodeChallenge(codeVerifier);

// Build the authorization request with PKCE parameters
AuthorizationRequest authRequest = new AuthorizationRequest.Builder()
        .clientId("your-client-id")
        .redirectUri("https://your-tomcat-app.com/callback")
        .scope("openid email profile")
        .codeChallenge(codeChallenge)
        .codeChallengeMethod("S256") // Use SHA-256 for the challenge
        .build();

// Store the code verifier in the user's server-side session (you'll need it later)
request.getSession().setAttribute("PKCE_CODE_VERIFIER", codeVerifier);

// Redirect the user to the Asgardeo authorization endpoint
String authUrl = authClient.buildAuthorizationUrl(authRequest);
response.sendRedirect(authUrl);
  1. Include the code verifier when exchanging the authorization code for tokens:
// Retrieve the authorization code from the callback request
String authCode = request.getParameter("code");
// Fetch the stored code verifier from the session
String codeVerifier = (String) request.getSession().getAttribute("PKCE_CODE_VERIFIER");

// Build the token request with the code verifier
TokenRequest tokenRequest = new TokenRequest.Builder()
        .authorizationCode(authCode)
        .redirectUri("https://your-tomcat-app.com/callback")
        .codeVerifier(codeVerifier)
        .build();

// Note: You don't need to include the client secret here for PKCE-enabled public clients
TokenResponse tokenResponse = authClient.requestToken(tokenRequest);

PKCE helps prevent authorization code interception attacks, so it’s highly recommended for any application that can’t securely store a client secret.

内容的提问来源于stack exchange,提问作者Enrico Perbellini

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 17:49:06