I was thinking mostly of ownCloud 10.
My motivation came from Re: [OAUTH-WG] Refresh tokens really. So setting an expiry and then letting the auth server update the share each time the short-lived token is refreshed could be a good start, yeah. But I think there may also be more sophisticated ways, if the short-lived token is some sort of JWT for instance, that proves possession of the refresh token.