This implementation just keeps the refresh token and only updates the access token. The spec says that this is allowed. There's really no reason to do this, other than the fact that it's easier.