[JIRA] (JOIDC-82) Dyn.reg. profile config setting secretExpirationPeriod is not honored

Henri Mikkonen (Jira) jira at shibboleth.atlassian.net
Thu Mar 17 12:29:29 UTC 2022


Henri Mikkonen ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A1614c4a5-c89e-4edc-9421-990bd6ea85fd ) *commented* on JOIDC-82 ( https://shibboleth.atlassian.net/browse/JOIDC-82?atlOrigin=eyJpIjoiMDNjMmVlNzcxMmFmNGMwYzlmOGQzMzEwMjYxZjAyMzkiLCJwIjoiaiJ9 )

Re: Dyn.reg. profile config setting secretExpirationPeriod is not honored ( https://shibboleth.atlassian.net/browse/JOIDC-82?atlOrigin=eyJpIjoiMDNjMmVlNzcxMmFmNGMwYzlmOGQzMzEwMjYxZjAyMzkiLCJwIjoiaiJ9 )

I’m not currently seeing any clear use case for expired secrets either, while keeping the overall RP record still alive.

The dynamic registration spec hints (see 4.3. in [1]) that client_secret could be updated even during a GET-call to the client configuration endpoint (which we don’t have yet - see JOIDC-48 ( https://shibboleth.atlassian.net/browse/JOIDC-48 ) Open ).

Before implementing the configuration endpoint, one option would be to simply add a note that the client expiration is not currently honored on the OP-side? Perhaps also change the code to remove the secret expiration timestamp from the record and the registration response message.

[1] https://openid.net/specs/openid-connect-registration-1_0.html

( https://shibboleth.atlassian.net/browse/JOIDC-82#add-comment?atlOrigin=eyJpIjoiMDNjMmVlNzcxMmFmNGMwYzlmOGQzMzEwMjYxZjAyMzkiLCJwIjoiaiJ9 ) Add Comment ( https://shibboleth.atlassian.net/browse/JOIDC-82#add-comment?atlOrigin=eyJpIjoiMDNjMmVlNzcxMmFmNGMwYzlmOGQzMzEwMjYxZjAyMzkiLCJwIjoiaiJ9 )

Get Jira notifications on your phone! Download the Jira Cloud app for Android ( https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail ) or iOS ( https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8 ) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100197- sha1:81e38da )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/commits/attachments/20220317/654d6dc0/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-comment-icon-f3793144-59b7-4e79-8a95-2fbc9f6b79d0
Type: image/png
Size: 1084 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220317/654d6dc0/attachment-0003.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-avatar-cfe20d4a-f094-4bee-a4a2-70e0a988d3ff
Type: image/png
Size: 425 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220317/654d6dc0/attachment-0004.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-footer-desktop-logo-758cdd31-1a4f-4ef2-83fc-50b42b3d08b0
Type: image/png
Size: 10805 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220317/654d6dc0/attachment-0005.png>


More information about the commits mailing list