OAuth 2.0 Clean-up Task
Task to clean up expired OAuth 2.0 / OpenID Connect tokens and sessions etc.
To minimize database locks, the task doesn't delete all expired items in one transaction but deletes the tokens in configurable batches.
It is recommended to schedule this task with a daily interval during a time with a low database load. Depending on the total number of tokens and the number of deletable OAuth 2.0 tokens, the task might take some time, but a proper "Batch Size" will keep row locks at a minimum.
sqlDataSource) batchSize) During cleanup, any expired entries are deleted in batches of this size. This ensures that any row locks on the database are very short-lived and do not affect parallel modifications. This value should not be set too high to prevent very long-running transactions.
Cleanup will repeatedly delete this number of database entries until all expired tokens, sessions, pushed authorization requests and client assertions have been removed. Therefore, this task can take some time when a lot of expired items are present.
This size should be chosen such that every batch does not take longer than 5 seconds. The average runtime of the batches can be found in the task's logs.
cleanupPushedAuthorizationRequests) If set to true, expired Pushed Authorization Requests will be removed during cleanup.
Note that if this is set to true, the database must contain an oauth2_par_request table; otherwise an exception will be thrown during cleanup.
cleanupAcceptedClientAssertions) If set to true, expired private key JWTs previously accepted as client_assertion during client authentication will be removed during cleanup.
Note that if this is set to true, the database must contain an oauth2_accepted_client_assertions table; otherwise an exception will be thrown during cleanup.
tokenTableName) tokenAssignmentTableName) logQueries) If enabled, all SQL queries executed during cleanup will be written to the module's corresponding log file. This is only effective if the log level is set to at least INFO.
Warning: query values (including potentially sensitive data) will be logged as well.
type: OAuth2CleanupTask
id: OAuth2CleanupTask-xxxxxx
displayName:
comment:
properties:
batchSize: 1000
cleanupAcceptedClientAssertions: true
cleanupPushedAuthorizationRequests: true
logQueries: false
sqlDataSource:
tokenAssignmentTableName: token_assignment
tokenTableName: token