In the ACCC draft rules it is specified that authorisation can be provided by a customer for "Single Use" as opposed to a duration of authorisation.
It is proposed that, for an authorisation that is "Single Use", only an access token will be returned and no refresh token will be returned. As a result, once the access token as expired, no further data retrieval will be possible and the authorisation is effectively also expired.
Does anyone have any concerns with this approach?
In the ACCC draft rules it is specified that authorisation can be provided by a customer for "Single Use" as opposed to a duration of authorisation.
It is proposed that, for an authorisation that is "Single Use", only an access token will be returned and no refresh token will be returned. As a result, once the access token as expired, no further data retrieval will be possible and the authorisation is effectively also expired.
Does anyone have any concerns with this approach?