Is there an existing issue for this?
Current Behavior
After removing client role restricted-access from user, you can continue get new pair of access and refresh tokens with refresh token
Expected Behavior
After removing client role restricted-access from user, you get "access-denied" error with refresh token
Steps To Reproduce
- make flow with extension (browser or direct access grant)
- give user role from client
- user authenticated (you get pair access, refresh tokens with browser flow or direct grant flow)
- remove role from user
- you can continue get pair of tokens with refresh_token
Version
- Keycloak: 25.0.6
- This extension: 25.0.0
Anything else?
No response
Is there an existing issue for this?
Current Behavior
After removing client role restricted-access from user, you can continue get new pair of access and refresh tokens with refresh token
Expected Behavior
After removing client role restricted-access from user, you get "access-denied" error with refresh token
Steps To Reproduce
Version
Anything else?
No response