diff --git a/src/main/java/com/authlete/common/dto/TokenRevokeRequest.java b/src/main/java/com/authlete/common/dto/TokenRevokeRequest.java index a5ed98fde..2bf60293b 100644 --- a/src/main/java/com/authlete/common/dto/TokenRevokeRequest.java +++ b/src/main/java/com/authlete/common/dto/TokenRevokeRequest.java @@ -79,6 +79,14 @@ * the API returns {@code 400 Bad Request}. *

* + * + *

+ * Bulk revocation with {@code clientIdentifier} only, {@code clientIdentifier} + {@code subject}, + * or {@code subject} only deletes at most {@code 20 tokens per request} + * (the default of {@code token.revoke.count.max} in {@code ServerConfiguration.java}). If the + * target has more than 20 tokens, the response {@code count} will be 20 and the remainder + * is left untouched. To fully wipe them, call the endpoint repeatedly until {@code count} returns 0. + *

* * @since 3.26 * @since Authlete 2.2.29 diff --git a/src/main/java/com/authlete/common/dto/TokenRevokeResponse.java b/src/main/java/com/authlete/common/dto/TokenRevokeResponse.java index 3286520b2..513aeae87 100644 --- a/src/main/java/com/authlete/common/dto/TokenRevokeResponse.java +++ b/src/main/java/com/authlete/common/dto/TokenRevokeResponse.java @@ -26,12 +26,19 @@ public class TokenRevokeResponse extends ApiResponse { private static final long serialVersionUID = 1L; - + /** + * If the + * target has more than 20 tokens, the response {@code count} will be 20 and the remainder + * is left untouched. To fully wipe them, call the endpoint repeatedly until {@code count} returns 0. + */ private int count; /** * Get the number of revoked tokens. + * If the + * target has more than 20 tokens, the response {@code count} will be 20 and the remainder + * is left untouched. To fully wipe them, call the endpoint repeatedly until {@code count} returns 0. * * @return * The number of revoked tokens. @@ -44,6 +51,9 @@ public int getCount() /** * Set the number of revoked tokens. + * If the + * target has more than 20 tokens, the response {@code count} will be 20 and the remainder + * is left untouched. To fully wipe them, call the endpoint repeatedly until {@code count} returns 0. * * @param count * The number of revoked tokens.