You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何无需重新登录,用refresh_token获取带新增scope的Cloudfoundry UAA新access_token?

OAuth 2.0 Standard & Cloud Foundry UAA: Refresh Tokens with Updated Scopes

Great question! Let’s break this down clearly—first for the standard OAuth 2.0 spec, then specifically how Cloud Foundry UAA handles this scenario.

Standard OAuth 2.0 Behavior

The OAuth 2.0 specification doesn’t enforce a strict rule here, but it gives authorization servers flexibility. Some implementations will lock the scope to what was granted during the initial login, while others will re-evaluate the user’s current permissions when a refresh token is used. The critical factor is whether the server checks the user’s latest access rights mid-refresh flow.

Cloud Foundry UAA’s Specific Support

Good news: UAA is built to handle exactly this scenario without requiring the user to re-login. Here’s the breakdown:

  • When you send a refresh token request to UAA, it doesn’t just reuse the original scope from the initial authorization. Instead, it rechecks the user’s current assigned permissions, groups, and scopes in real time.
  • If the user has been granted new scopes since the initial access token was issued, the new access token returned by the refresh flow will automatically include these additional scopes—no extra steps needed.

Example Refresh Token Request

To test this, you can use a simple POST request to UAA’s token endpoint (replace placeholders with your actual values):

curl -X POST https://your-uaa-instance.example.com/oauth/token \
  -u "your-client-id:your-client-secret" \
  -d "grant_type=refresh_token&refresh_token=your-existing-refresh-token"

The response’s scope field will reflect the user’s current full set of authorized scopes, including any newly added ones.

Key Notes

  • This only works if the refresh token is still valid (not expired, revoked, or invalidated by admin action).
  • If you explicitly specify a scope parameter in the refresh request, UAA will return the intersection of the specified scopes and the user’s current authorized scopes. To get all updated scopes, omit the scope parameter entirely.

内容的提问来源于stack exchange,提问作者Amit Teli

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 04:11:22