Hi,
I have a problem with offline tokens. Some of them expire well before the limit. My offline tokens have an expiration period of 190 days (Offline Session Idle = 190d and Offline Session Max = 190d). To obtain them, my user goes through the authorization code grant flow and consents. The tokens are stored in a database and exchanged for access tokens with a client_id client_secret.
my users sometimes have this error that I cannot explain :
{ "error": "invalid_grant", "error_description": "Session doesn't have required client" }I’m running keycloak 15.1.1 on a Kubernetes cluster of 3 nodes. The CACHE_OWNER parameter is 2
I’m using lazy loading Offline token with this setting :
An idea ?
Thanks
Sebastien
This happens when the offline user session is still found but the related offline client session is not found. Lazy loading only works if the offline user session is not in the cache, then it also automatically loads all related client offline sessions. If the offline user session is in the cache but the client offline session was evicted, you will run into that problem. Have you configured any eviction for your caches (like putting a limit on the cache size)?
Best regards,
Sebastian
Mit freundlichen Grüßen / Best regards
Dr.-Ing. Sebastian Schuster
Product Area User Management (IOC/PAU1)
Robert Bosch GmbH | Postfach 10 60 50 | 70049 Stuttgart | GERMANY |
www.bosch.com
Tel. +49 30 726112-485 | Mobil +49 152 02177668 | Telefax +49 30 726112-100 |
Sebastian...@bosch.io
Sitz: Stuttgart, Registergericht: Amtsgericht Stuttgart, HRB 14000;
Aufsichtsratsvorsitzender: Franz Fehrenbach; Geschäftsführung: Dr. Volkmar Denner,
Prof. Dr. Stefan Asenkerschbaumer, Filiz Albrecht, Dr. Christian Fischer, Dr. Stefan Hartung,
Dr. Markus Heyn, Harald Kröger, Rolf Najork
--
You received this message because you are subscribed to the Google Groups "Keycloak User" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
keycloak-use...@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/keycloak-user/0aa56de1-85da-458f-bb84-01c4e4b5553dn%40googlegroups.com.
Might be. Could cause some data to not be replicated correctly…
To view this discussion on the web visit https://groups.google.com/d/msgid/keycloak-user/591e92c8-2679-461d-a2b9-f2b4a52bd328n%40googlegroups.com.
You received this message because you are subscribed to a topic in the Google Groups "Keycloak User" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/keycloak-user/sQWbImxUYqU/unsubscribe.
To unsubscribe from this group and all its topics, send an email to keycloak-use...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/keycloak-user/a30d99d1-029e-4935-952c-003d01cbfda7n%40googlegroups.com.