使用FusionAuth授权码模式获取AccessToken时未返回RefreshToken求助
Problem Details
I'm using FusionAuth for authentication and have set up an OAuth-configured application. My authorization URL is:http://localhost:9011/oauth2/authorize?access_type=offline&prompt=consent&response_type=code&client_id=9ecc54b7-6f79-4105-a208-ca61e6157b58&redirect_uri=http%3A%2F%2Flocalhost%3A8080%2Fipos%2Frest%2FfusionAuth%2FcallBack
After accessing this URL and entering credentials, the callback hits my Java Jersey API endpoint with these parameters:
code: dZgq5Xd0YmAQXZ2JIzkih832iojimgLUPwT7yoH9-TYlocale: en_USuserState: AuthenticatedNotRegistered
I'm using the Scribe Java library to handle OAuth flow. When exchanging the authorization code for an access token (with grant_type=authorization_code), the response looks like this:
{ "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImRRZTA1Uk1vN19oVjZUUnpLVUQ1aXpRU2NSOCJ9.eyJhdWQiOiI5ZWNjNTRiNy02Zjc5LTQxMDUtYTIwOC1jYTYxZTYxNTdiNTgiLCJleHAiOjE1Nzc3MTg0NjgsImlhdCI6MTU3NzcxODM0OCwiaXNzIjoiYWNtZS5jb20iLCJzdWIiOiI3ZWE3OWRhZi1hZjExLTQ1MTUtODljYS1iOGFjYTFjN2I5YTEiLCJhdXRoZW50aWNhdGlvblR5cGUiOiJQQVNTV09SRCIsImVtYWlsIjoiZGhhdmFsYmhvb3Q5M0BnbWFpbC5jb20iLCJlbWFpbF92ZXJpZmllZCI6dHJ1ZSwicHJlZmVycmVkX3VzZXJuYW1lIjoiZGhhdmFsYmhvb3QifQ.eA0Xi6nEZhWaTMd-P26ESdE3NsyXNRNVBKBdBvHxvzfHgXYJiN2pf-16mY8JK-4-1g3vZF7Cwv-SkP4iZAIJCYYc3uBW8Qlcjjn9cyi7_RggBBBsErcs2acRIt-D5NpnVJfkxHwGAs9fO6a2Win98GGYyv1nzBG9OhWkyZJTy4QxzlgXNrkQIzTuzRwLkRFzKCT95pqfsOYb_MXPuAksg5q1SHIj8qtbO7EO-vMbpmiok1C-Wflbiq2X_tq17QBKbO4JAMLm9_pCZse1tqLyNP4fIh3VHTz7OdbbXvug2Tpk_yTWLVL_29XC87-91R5iXeezLjADkdi1yXMUdHioOw", "expires_in": 119, "token_type": "Bearer", "userId": "7ea79daf-af11-4515-89ca-b8aca1c7b9a1" }
No matter if it's the user's first login or subsequent ones, the response never includes a refresh_token. I've already shortened the JWT expiration to 120 seconds and enabled the "Generate refresh tokens" option in the application's OAuth settings. I'm stuck on this issue—any help would be appreciated.
Let's work through this step by step, since you've already checked the main FusionAuth setting ("Generate refresh tokens") and added access_type=offline to your auth URL.
Verify the
access_type=offlineparameter is actually being sent
Your auth URL hasaccess_type=offlinebut uses&(HTML-escaped ampersands). Make sure when the request is sent to FusionAuth, this parameter is properly parsed. Sometimes escaped characters can cause the parameter to be ignored. Use a tool like Chrome DevTools (Network tab) to inspect the actual authorization request URL—confirmaccess_type=offlineis present as a query parameter without any escaping issues.Ensure Scribe Java is properly including the
access_typeparameter
Scribe's default OAuth2 flow might not handle theaccess_typeparameter out of the box. You'll need to explicitly add it when building the authorization URL or configuring yourOAuthService. Here's how to do it:// Example: Adding custom parameters to the authorization URL OAuthService service = new ServiceBuilder("your-client-id") .apiSecret("your-client-secret") .callback("your-redirect-uri") .build(FusionAuthApi.instance()); // You'll need a custom Api class for FusionAuth // Explicitly add access_type and prompt parameters Map<String, String> additionalParams = new HashMap<>(); additionalParams.put("access_type", "offline"); additionalParams.put("prompt", "consent"); String authUrl = service.getAuthorizationUrl(additionalParams);If your Scribe version is older, you might need to manually append the parameters to the URL string to ensure they're included.
Double-check FusionAuth application settings
Beyond enabling "Generate refresh tokens", confirm these settings:- In your application's Token Configuration, ensure the
Refresh token TTLis set to a non-zero value (e.g., 86400 seconds for 1 day). If this is 0 or empty, FusionAuth won't generate a refresh token. - Confirm Grant Types includes
Authorization Code(you're already using this, but it's worth a quick check).
- In your application's Token Configuration, ensure the
Test with a clean session
Even withprompt=consent, cached user sessions might prevent FusionAuth from issuing a refresh token. Try initiating the flow in incognito/private browsing mode, or clear your browser's cookies/cache for the FusionAuth domain. This ensures you're starting a fresh authorization flow.Validate the token exchange request (bypass Scribe temporarily)
To rule out Scribe as the issue, test the token exchange directly with a tool like Postman:- Method: POST
- URL:
http://localhost:9011/oauth2/token - Headers:
Content-Type: application/x-www-form-urlencoded- For confidential applications, add
Authorization: Basic [base64-encoded client_id:client_secret]
- Form Data:
grant_type:authorization_codecode: Your authorization code from the callbackredirect_uri: Your exact callback URLclient_id: Your application's client IDclient_secret: Your application's client secret (if confidential)
If Postman returns a
refresh_token, the problem is in your Scribe configuration. If not, the issue is with your FusionAuth setup or initial authorization request.
The most common culprit here is the access_type=offline parameter not being correctly passed to FusionAuth. Start with verifying the actual request parameters, then work through the other steps to narrow down the issue.
内容的提问来源于stack exchange,提问作者Dhaval Bhoot

