Yet another great contribution by @herglotzmarco brings us the option to set stricter API token invalidation settings. You now have an additional attribute in the token invalidation task which sets an upper limit for how long a token can be active before an interactive refresh via UI is required.
In addition, the README has been enhanced with information about an alternative OAuth2 Proxy configuration which allows access using Bearer tokens.
If you have an SMTP server configured with Nexus you can now also let users get notified when their API tokens expired.