[JIRA] (JOIDC-21) Use token authentication for OIDC dynamic client registration
Scott Cantor (Jira)
jira at shibboleth.atlassian.net
Thu Mar 10 18:33:28 UTC 2022
Scott Cantor ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A5b78efc9-1379-42cc-a3f6-56c6ea3a0007 ) *commented* on JOIDC-21 ( https://shibboleth.atlassian.net/browse/JOIDC-21?atlOrigin=eyJpIjoiZmM0NzI0N2Q2ZGU0NDFiZDlkMzVjZWM5Y2I0YTM5OTgiLCJwIjoiaiJ9 )
Re: Use token authentication for OIDC dynamic client registration ( https://shibboleth.atlassian.net/browse/JOIDC-21?atlOrigin=eyJpIjoiZmM0NzI0N2Q2ZGU0NDFiZDlkMzVjZWM5Y2I0YTM5OTgiLCJwIjoiaiJ9 )
My vision for this is to allow pre-registration of client_id and allow a model where developers can authenticate to the endpoint to get their tokens with an authorization check based on what client_id is involved (if any).
This has already been implemented on the registration endpoint if the token contains the client_id, and the ability to replace existing metadata with the same client_id was added if the token authorizes that. If we want to carry through additional “initial/default” claims for the client metadata through the access token we should be able to do that easily enough.
This should also address the gap of not being able to update client metadata, provided we accept that this will never work with automated clients since the specs for all this are too vague.
( https://shibboleth.atlassian.net/browse/JOIDC-21#add-comment?atlOrigin=eyJpIjoiZmM0NzI0N2Q2ZGU0NDFiZDlkMzVjZWM5Y2I0YTM5OTgiLCJwIjoiaiJ9 ) Add Comment ( https://shibboleth.atlassian.net/browse/JOIDC-21#add-comment?atlOrigin=eyJpIjoiZmM0NzI0N2Q2ZGU0NDFiZDlkMzVjZWM5Y2I0YTM5OTgiLCJwIjoiaiJ9 )
Get Jira notifications on your phone! Download the Jira Cloud app for Android ( https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail ) or iOS ( https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8 ) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100197- sha1:b6de2d8 )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/commits/attachments/20220310/8d6ecd5a/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-avatar-9febd3b8-1c70-4ca7-9083-23972e518959
Type: image/png
Size: 341 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220310/8d6ecd5a/attachment-0003.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-comment-icon-9bc09fd1-8d7f-4f79-a45d-839dfb9a7a3d
Type: image/png
Size: 1084 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220310/8d6ecd5a/attachment-0004.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-footer-desktop-logo-e72c57ef-cb6f-4558-b10e-dd28a35491aa
Type: image/png
Size: 10805 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220310/8d6ecd5a/attachment-0005.png>
More information about the commits
mailing list