Assert minimum JWT expiration time

This commit is contained in:
Viktor Egorov
2025-03-07 12:01:57 +01:00
parent f1c83ef113
commit 9be59bd83f

View File

@@ -173,6 +173,10 @@ public final class JwtAccessTokenBuilder implements AccessTokenBuilder {
// add scope to custom claims
Scopes.toClaims(customClaims, scope);
if (expiresIn < 1) {
expiresIn = 1;
}
Instant now = clock.instant();
long expiration = expiresInUnit.toMillis(expiresIn);