Overview
Riva Insight includes support for Salesforce's enhanced OAuth security requirements, including:
- Proof Key for Code Exchange (PKCE)
- Refresh Token Rotation (RTR)
These industry-standard security enhancements strengthen authentication security, reduce the risk of credential misuse, and help ensure continued compatibility with Salesforce's evolving security standards.
Proof Key for Code Exchange (PKCE)
- Proof Key for Code Exchange (PKCE) strengthens OAuth authentication by adding an additional verification step during the authorization process. This helps protect against authorization code interception attacks and provides stronger security during Salesforce authentication.
Refresh Token Rotation (RTR)
- Refresh Token Rotation enhances security by issuing a new refresh token each time an access token is renewed. Once a new refresh token is issued, the previous refresh token becomes invalid.
- This approach reduces the value of compromised credentials and aligns with modern security best practices for cloud applications and connected services.
Why Is Riva Making This Change?
Salesforce has introduced enhanced OAuth security requirements for connected applications, including PKCE and Refresh Token Rotation. To maintain compatibility with Salesforce and continue providing secure integrations, Riva has implemented support for these requirements across the platform.
Impacted Users
These changes affect customers using Salesforce integrations with Riva Insight.
Administrators and end users may notice changes in authentication behavior as Salesforce's enhanced security requirements are adopted and as Riva continues to enhance support for Salesforce Refresh Token Rotation.
- Proof Key for Code Exchange has been applied across all cloud environments
- Refresh Token Rotation has only been applied to shared tenants at this time
Benefits of These Security Enhancements
Implementing PKCE and Refresh Token Rotation provides several benefits:
- Stronger protection against token theft and replay attacks.
- Enhanced security for Salesforce-connected applications.
- Reduced risk associated with long-lived authentication credentials.
- Alignment with Salesforce's current and future security requirements.
- Improved compliance with modern enterprise security standards.
Behavioral Changes
More Frequent Salesforce Sign-Ins
Some users may currently be prompted to reconnect their Salesforce account or sign in more frequently than in previous releases. This behavior is related to Salesforce Refresh Token Rotation, which changes how refresh tokens are issued, renewed, and invalidated.
As Riva continues to enhance support for Salesforce Refresh Token Rotation, improvements are being implemented to reduce these occurrences while maintaining compliance with Salesforce's security requirements.
Current Limitations
Restricted Salesforce Administration Functions
Salesforce administration functions within the Admin UI have been temporarily restricted when accessed through the Riva Cloud management interface. These temporary restrictions help ensure reliable Salesforce synchronization as Riva continues to enhance support for Salesforce Refresh Token Rotation.
Riva is actively working on a hotfix to restore the affected functionality while preserving compatibility with Salesforce's enhanced security requirements and maintaining synchronization reliability.
What Riva Is Doing
Current initiatives include:
- Improving refresh token management.
- Reducing unnecessary Salesforce reconnect prompts and sign-in requests.
- Improving session resiliency and continuity.
Restoring temporarily restricted Admin UI functionality.