Shib IdP OIDC - PKCE

Cantor, Scott cantor.2 at osu.edu
Thu Jul 15 19:17:56 UTC 2021


On 7/15/21, 3:14 PM, "users on behalf of Mak, Steve" <users-bounces at shibboleth.net on behalf of makst at upenn.edu> wrote:

>    If yes how do you do it? With OIDC v2 I thought it did have PKCE support.

I can say for certain that if it did then it does now. The old docs apparently mention it so I'm fairly certain it still does and for now I guess the original docs [1] would be the best way to attempt it until/unless the docs are updated.

Assuming you manage it, perhaps you can trial out getting into the new wiki and improving things, I wouldn't be a great candidate to try to document it.

-- Scott

[1] https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/OIDC.SSO#case-example-force-pkce-and-allow-unauthenticated-token-endpoint-calls-for-one-rp



More information about the users mailing list