Angaben zum Datum
Datum aus der Quelle.
Aufgenommen am .
Auth0: Refresh Tokens werden künftig länger
Auth0 erhöht die Entropie neu ausgestellter Refresh Tokens, sodass diese länger als die bisherigen ca. 45 Zeichen werden und feste Längenprüfungen, Spalten mit fester Breite oder Regex-Längenlimits angepasst werden sollten.
As part of our commitment to maintaining the highest security and compliance standards, we will soon be updating our authentication service configuration to increase the length and entropy of our refresh tokens. ## What is changing? We are increasing the cryptographic entropy of our issued Refresh Tokens. As a result, the string length of newly issued Refresh Tokens will increase beyond the current ~45-character baseline. ## Why is this changing? Higher entropy ensures that refresh tokens are even more resilient against brute-force attacks and key-guessing attempts. [Auth0's lifecycle policies](https://auth0.com/docs/troubleshoot/product-lifecycle#backward-compatible-non-breaking-changes) explicitly note that token formats and lengths are non-deterministic and subject to change without deprecation notices. However, we want to proactively notify you to ensure a seamless transition for your integrations. ## Who is impacted? You may be impacted if your client applications, APIs, or database schemas perform any of the following: - __Hardcoded length checks__: Validating that a token string is strictly 45 characters long. - __Fixed-size database storage__: Storing refresh tokens in fixed-width columns (e.g., VARCHAR(45) or CHAR(45)). - __Regex validation__: Employing regex patterns that enforce a maximum length limit. ## Recommended Actions - Remove strict length validations: Treat refresh tokens as variable-length opaque strings. - Update database storage: Ensure co…