GEANT OIDC-work status
Cantor, Scott
cantor.2 at osu.edu
Tue Nov 14 09:25:18 EST 2017
> May I ask why you went with the implicit flow first (instead of the
> authorisation code flow)? Do you plan to support the other flows too?
The reason they started there was that it's much simpler to implement and matches the predominant SAML use case so it's easier to adapt the SAML examples to make it work.
I am extremely curious as to how people plan to test upgrades or changes in a world of back channel flows. There's a reason we stopped using them and I'm extremely loathe to go back to that. It's one thing to do it as a RP because that's what Google insists on, but it's a bad model to follow if we have the choice. I really think it's misguided if we're going to do a profile for higher ed to codify what we already learned a long time back was a mistake.
-- Scott
More information about the dev
mailing list