I am currently build a security service that issue jwt token and refresh token using asp.net and microsoft jwt library. My question are, I have refresh token from users that store in db:
- Should I replace refresh token each time user request for new access token by using current refresh token or just mark that refresh token that is revoked or some kind of flag?
- Should I delete or mark it with flag when there is a request for revoking token?
Thanks.