OIDC extension: refresh and validate endpoints?
Wessel, Keith
kwessel at illinois.edu
Fri Aug 30 15:37:56 EDT 2019
Thanks, Liam. And would that use the same session storage as my IdP’s session storage for SAML-based sessions? I assume they’re the same.
Keith
From: users <users-bounces at shibboleth.net> On Behalf Of Liam Hoekenga
Sent: Friday, August 30, 2019 2:28 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: OIDC extension: refresh and validate endpoints?
One more question based on what Liam brought up: what property controls the storage service to use for refresh tokens? I don’t see a storage setting for this in idp-oidc.properties. I only see dynamic registrations, remote JWK sets, and the revocation cache which, obviously, all must be server-side.
I'm pretty sure it they just use the same storage service that the rest of the tokens use (session storage)
Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190830/1dfc60f6/attachment.html>
More information about the users
mailing list