API access token revocation (1.7.0)
A security improvement to privileged authentication in the Spaaza API.
- Fixed the checks made on each request that uses privileged (Bearer access token) authentication. A request is now rejected if the access token is inactive or deleted, or if the service client that owns the access token is disabled or deleted. Previously such a request could still authenticate for a period of time after the token or service client was revoked. See access token revocation.
- Changed the error returned for a request made with a revoked access token, or with an access token of a disabled or deleted service client. Such requests now return
access_token_invalid(code 266, HTTP status 401) at authentication time instead ofaccess_denied(code 424). This change is not tied to an API version. API clients that check foraccess_deniedin this situation should check foraccess_token_invalidinstead.