Ktor JWT authentication interoperability with custom token refresh handler
27.9K reputation · 20 Nov 2022, 11:00 UTC
Goal: Determine if Ktor’s JWT authentication plugin should automatically invoke a developer‑supplied token refresh callback when it encounters an expired JWT, thereby preserving least‑privilege access without requiring manual pipeline modifications.
Current behavior: The plugin returns 401 Unauthorized for expired tokens unless the application explicitly adds a refresh step; developers implement this in various places, leading to inconsistent handling and uncertainty about where responsibility lies.
- Should the JWT plugin expose an optional refresh handler that is triggered on 401 responses caused by token expiration?
- How would automatic invocation affect existing authentication pipelines, security guarantees, and backward compatibility?
- What versioning considerations exist for enabling such behavior by default versus keeping it opt‑in?