Spring Boot JWT:刷新令牌与注销API实现及移动端问题咨询
Hey there! Making the switch from Basic Auth to JWT is a smart fix for that memory overload issue—let’s break down your three key questions with mobile-specific considerations:
1. How long should access tokens be valid?
For mobile apps, 15 to 30 minutes is the sweet spot. Here’s why:
- Short-lived tokens minimize damage if stolen—there’s a tiny window for attackers to misuse them.
- Mobile users expect seamless experiences (like Twitter’s background feed updates), so your app can quietly refresh the access token using the refresh token before it expires, no login prompts needed.
- Skip overly short lifespans (like 5 minutes)—you’ll flood your server with refresh requests and defeat JWT’s efficiency.
2. What’s a good refresh token lifespan?
This ties to your app’s "remember me" behavior:
- For users who opt into "remember me," go with 7 to 30 days. Longer refresh tokens mean less frequent logins, which boosts user retention.
- For standard sessions (no remember me), 1 to 7 days is reasonable.
- Critical refresh token rules:
- Store them securely on Android! Use the Android Keystore system instead of plaintext SharedPreferences—this blocks access if the device is rooted.
- Rotate refresh tokens: every time you issue a new access token, replace the old refresh token with a new one. This limits harm if a refresh token gets compromised.
3. How to handle logout and stolen tokens?
JWT is stateless by default, so deleting tokens on the mobile side isn’t enough if they’re still valid. Here’s a robust approach:
Logout flow
When the user taps logout:
- Delete both access and refresh tokens from the mobile device’s secure storage.
- Send a logout request to your Spring Boot server, adding both tokens to a token blacklist (use Redis for this—it’s fast and supports TTL, so entries auto-expire when the token’s original lifespan ends).
Handling stolen tokens
If a user reports a stolen account or you spot suspicious activity (like an unfamiliar location login):
- Immediately add all valid access/refresh tokens for that user to the blacklist.
- Force a full re-login across devices—store user-refresh token mappings in your database to invalidate all tokens at once.
- Extra safeguards:
- Bind refresh tokens to a unique device ID (generated securely on first launch). Reject refresh token requests from unrecognized devices and prompt re-authentication.
- Add a "revoke all sessions" button in app settings—let users manually invalidate all active tokens if they suspect foul play.
Quick Spring Boot snippet for token blacklisting
Here’s how to check and blacklist tokens with Redis:
@Autowired private StringRedisTemplate redisTemplate; public boolean isTokenBlacklisted(String token) { return redisTemplate.hasKey("blacklist:" + token); } public void blacklistToken(String token, long expirationSeconds) { redisTemplate.opsForValue() .set("blacklist:" + token, "invalid", expirationSeconds, TimeUnit.SECONDS); }
Call blacklistToken on logout or token invalidation, and have your authentication filter run isTokenBlacklisted before processing any request.
内容的提问来源于stack exchange,提问作者Manu

