Base solution for your next web application
Open Closed

token_validity_key Cache size #12402


User avatar
0
ajayak created

Is this normal to have this many caches for token_validity_key?

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

5 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @ajayak

    Could you please verify if the Expire Time for TokenValidityKey is specified in the CreateJwtClaims method within the TokenAuthController? Additionally, could you confirm if a deletion process for TokenValidityKey, as outlined below, is being performed in the LogOut method in your project?

    var tokenValidityKeyInClaims = User.Claims.First(c => c.Type == AppConsts.TokenValidityKey);
    await RemoveTokenAsync(tokenValidityKeyInClaims.Value);
    
    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    ajayak created

    Hi @oguzhanagir,

    There is no change made by me in TokenAuthController.cs class. It's all framework code. The Logout method contains the code to remove token and CreateJwtClaims contains the logic to add the expiration time for all tokens. Note: I'm using Redis cache.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @ajayak

    Thank you for your feedback. We have created an issue for this. You can follow the developments here. Thank you.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    ajayak created

    Thankyou

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @ajayak

    Two different keys, AccessToken and RefreshToken, are added to the token_validity_key cache. The default expiration time for the AccessToken is set to 1 day, while the RefreshToken is configured to be stored in the cache for 365 days.

    In some cases, users do not manually log out of the application, which causes old data related to the token_validity_key to remain in the cache. Therefore, it is recommended to reduce the cache expiration time for the RefreshToken.

    You can do this by changing the value of RefreshTokenExpiration located under the AppConst class in your application.

    If you only want to reduce the duration the token is kept in the cache, you can adjust the expiration value in the CreateJwtClaims method within the TokenAuthController class.

    Thank you

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)