I can not agree about the code bleow : tokenList[postData.refreshToken].token = token which would leak the Refresh Token