diff --git a/auth-server-password.md b/auth-server-password.md index 501e85c0..69c4bb9d 100755 --- a/auth-server-password.md +++ b/auth-server-password.md @@ -59,7 +59,7 @@ $grant = new \League\OAuth2\Server\Grant\PasswordGrant( $refreshTokenRepository ); -$grant->setRefreshTokenTTL(new \DateTime('P1M')); // refresh tokens will expire after 1 month +$grant->setRefreshTokenTTL(new \DateInterval('P1M')); // refresh tokens will expire after 1 month // Enable the password grant on the server $server->enableGrantType( diff --git a/terminology.md b/terminology.md index 27b5c32e..785ddb75 100755 --- a/terminology.md +++ b/terminology.md @@ -12,5 +12,6 @@ permalink: /terminology/ * `Client` - An application which accesses protected resources on behalf of the resource owner (such as a user). The client could be hosted on a server, desktop, mobile or other device. * `Grant` - A grant is a method of acquiring an access token. * `Resource server` - A server which sits in front of protected resources (for example "tweets", users' photos, or personal data) and is capable of accepting and responsing to protected resource requests using access tokens. +* `Resource owner` - The user who authorizes an application to access their account. The application's access to the user's account is limited to the "scope" of the authorization granted (e.g. read or write access). * `Scope` - A permission. * `JWT` - A JSON Web Token is a method for representing claims securely between two parties as defined in [RFC 7519](https://tools.ietf.org/html/rfc7519).