[JIRA] (JOIDC-21) Use token authentication for OIDC dynamic client registration

Scott Cantor (Jira) jira at shibboleth.atlassian.net
Thu Mar 10 19:22:03 UTC 2022


Scott Cantor ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A5b78efc9-1379-42cc-a3f6-56c6ea3a0007 ) *commented* on JOIDC-21 ( https://shibboleth.atlassian.net/browse/JOIDC-21?atlOrigin=eyJpIjoiNGU5NDdlM2IzYTAzNGVjYzk2YzQ0NjY4MTNjMDYzNDgiLCJwIjoiaiJ9 )

Re: Use token authentication for OIDC dynamic client registration ( https://shibboleth.atlassian.net/browse/JOIDC-21?atlOrigin=eyJpIjoiNGU5NDdlM2IzYTAzNGVjYzk2YzQ0NjY4MTNjMDYzNDgiLCJwIjoiaiJ9 )

Liam Hoekenga ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3Acb0f0ab4-8d2d-447d-98fa-6250c50c368c ) Keith Wessel ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=60ad392bb4624d00692388ed ) Is the issue here that you don’t trust the people you’re issuing the tokens to to register accurate contact information? It seems like that’s a slippery slope and it would be better to leave that to the client registration step. Otherwise you may as well just register all of the client information and be done with it because you can’t trust them.

I guess ultimately we can open this up to all sorts of parameters on the token issuing endpoint, but ultimately that means a pretty generic authorization check that has to approve any/all such values to get them into the token.

I think your/Henri’s initial idea for this was that the endpoint would only be used by the IdP admin, but my thoughts are it should also be usable directly by the app developers (after authentication of course) and they’d just request their own tokens. At that point it’s not too sensible to try and limit what contact information they would supply later for their clients.

( https://shibboleth.atlassian.net/browse/JOIDC-21#add-comment?atlOrigin=eyJpIjoiNGU5NDdlM2IzYTAzNGVjYzk2YzQ0NjY4MTNjMDYzNDgiLCJwIjoiaiJ9 ) Add Comment ( https://shibboleth.atlassian.net/browse/JOIDC-21#add-comment?atlOrigin=eyJpIjoiNGU5NDdlM2IzYTAzNGVjYzk2YzQ0NjY4MTNjMDYzNDgiLCJwIjoiaiJ9 )

Get Jira notifications on your phone! Download the Jira Cloud app for Android ( https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail ) or iOS ( https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8 ) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100197- sha1:b6de2d8 )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/commits/attachments/20220310/6742a52d/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-avatar-e2e29e64-138a-4e2b-8309-0f5b10e45656
Type: image/png
Size: 341 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220310/6742a52d/attachment-0003.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-comment-icon-dc3bee16-696e-4af5-983c-442623eaba08
Type: image/png
Size: 1084 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220310/6742a52d/attachment-0004.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-footer-desktop-logo-f51a935a-e47b-4328-a5cc-8d32aa926e3a
Type: image/png
Size: 10805 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220310/6742a52d/attachment-0005.png>


More information about the commits mailing list