Issue
- Sometimes users are unable to log in because their OAuth2 tokens receive a 401 "Unauthorized" response.
- This seems to happen randomly, and the tokens should be valid.
Environment
- Liferay DXP
Resolution
- OAuth2 token authorization may fail if the token issue timestamp is slightly after the server's current timestamp
- e.g. If the token is issued at
04:54:38.0and the Liferay server timestamp is at04:54:37.496.
- e.g. If the token is issued at
- This can happen if the servers aren't strictly time-synced.
- If this is the cause of failure, it can be resolved by time-syncing the Liferay server with the OAuth2 token issuer server.
Additional Information
Your method for time-syncing servers will depend on your specific architecture, but below are some links to common third party resources on time-syncing.