invalid_grant error in refresh token endpoint leading to memory leak
28K reputation · 24 Mar 2021, 11:24 UTC
When an OAuth authorization server returns the invalid_grant error for a refresh token request, some implementations retain request‑specific objects in memory because the error path does not invoke the same cleanup routines used for successful token responses. This can produce a gradual memory increase under repeated invalid refresh attempts. At the same time, the OAuth community debates whether servers should enforce mandatory refresh‑token rotation on each use to limit token theft, a measure the spec permits but does not require. The unresolved question is how to balance leak‑free error handling with the security benefits (and possible compatibility costs) of compulsory rotation.
What specific resource‑release steps must be added to the invalid_grant handling path to guarantee no memory growth? Does enforcing refresh‑token rotation amplify the risk of leaks if error handling remains inconsistent? How can implementers verify that both fixes coexist without degrading token‑endpoint latency or breaking legacy clients?