You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot JWT:刷新令牌与注销API实现及移动端问题咨询

JWT Best Practices for Your Twitter-like Android App

Hey there! Making the switch from Basic Auth to JWT is a smart fix for that memory overload issue—let’s break down your three key questions with mobile-specific considerations:

1. How long should access tokens be valid?

For mobile apps, 15 to 30 minutes is the sweet spot. Here’s why:

  • Short-lived tokens minimize damage if stolen—there’s a tiny window for attackers to misuse them.
  • Mobile users expect seamless experiences (like Twitter’s background feed updates), so your app can quietly refresh the access token using the refresh token before it expires, no login prompts needed.
  • Skip overly short lifespans (like 5 minutes)—you’ll flood your server with refresh requests and defeat JWT’s efficiency.

2. What’s a good refresh token lifespan?

This ties to your app’s "remember me" behavior:

  • For users who opt into "remember me," go with 7 to 30 days. Longer refresh tokens mean less frequent logins, which boosts user retention.
  • For standard sessions (no remember me), 1 to 7 days is reasonable.
  • Critical refresh token rules:
    • Store them securely on Android! Use the Android Keystore system instead of plaintext SharedPreferences—this blocks access if the device is rooted.
    • Rotate refresh tokens: every time you issue a new access token, replace the old refresh token with a new one. This limits harm if a refresh token gets compromised.

3. How to handle logout and stolen tokens?

JWT is stateless by default, so deleting tokens on the mobile side isn’t enough if they’re still valid. Here’s a robust approach:

Logout flow

When the user taps logout:

  1. Delete both access and refresh tokens from the mobile device’s secure storage.
  2. Send a logout request to your Spring Boot server, adding both tokens to a token blacklist (use Redis for this—it’s fast and supports TTL, so entries auto-expire when the token’s original lifespan ends).

Handling stolen tokens

If a user reports a stolen account or you spot suspicious activity (like an unfamiliar location login):

  1. Immediately add all valid access/refresh tokens for that user to the blacklist.
  2. Force a full re-login across devices—store user-refresh token mappings in your database to invalidate all tokens at once.
  • Extra safeguards:
    • Bind refresh tokens to a unique device ID (generated securely on first launch). Reject refresh token requests from unrecognized devices and prompt re-authentication.
    • Add a "revoke all sessions" button in app settings—let users manually invalidate all active tokens if they suspect foul play.

Quick Spring Boot snippet for token blacklisting

Here’s how to check and blacklist tokens with Redis:

@Autowired
private StringRedisTemplate redisTemplate;

public boolean isTokenBlacklisted(String token) {
    return redisTemplate.hasKey("blacklist:" + token);
}

public void blacklistToken(String token, long expirationSeconds) {
    redisTemplate.opsForValue()
        .set("blacklist:" + token, "invalid", expirationSeconds, TimeUnit.SECONDS);
}

Call blacklistToken on logout or token invalidation, and have your authentication filter run isTokenBlacklisted before processing any request.


内容的提问来源于stack exchange,提问作者Manu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 07:24:23