OIDC in 4.1.0 and problems with claims

Cantor, Scott cantor.2 at osu.edu
Wed Apr 7 12:59:06 UTC 2021


On 4/7/21, 8:56 AM, "users on behalf of Darren Boss" <users-bounces at shibboleth.net on behalf of darren.boss at computecanada.ca> wrote:

>    RIght, it wasn't in the docs but in the comment above the
>    idp.oidc.encodeConsentInTokens line in oidc.properties
>    # Store user consent to authorization code & access/refresh tokens
>    instead of exploiting consent storage

Yes, I added it to the profile settings page for the Authorization flow.

>    So, try setting encodeConsentInTokens to true and enabling the consent
>    post login flow again?

If you want to test it pathologically, yes, that's supposed to work. It's a lot of code to support something that's not really practical, but... 

-- Scott




More information about the users mailing list