Solutionunvalidated

Encrypting the refresh token is a good idea — without the need for a database. Tension: If you know that this will not happen to your users. Outcome: that approach might be ok.

0f4675d4-ae03-4e1b-80ea-aa6df89a6af5

Encrypting the refresh token is a good idea — without the need for a database. Tension: If you know that this will not happen to your users. Outcome: that approach might be ok.