OIDC claims missing after upgrade to IdP 4.1
Cantor, Scott
cantor.2 at osu.edu
Wed Jul 21 01:27:58 UTC 2021
On 7/20/21, 9:22 PM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:
> We do use a database for storing consent decisions, but obviously, the consent post authentication flow isn't
> enabled for any of the token or userinfo non-browser profiles. I think I'm missing your point, though, on this.
> Can you explain, please?
There's a setting to encode attributes into the tokens so that they can be recovered without having to resolve them again, and I was thinking maybe that triggered a bug in the consent enforcement.
The tokens can also store the consent decisions I think to allow client side consent storage to work but I really don't know all the options or how they work.
Somewhere in some mix of settings is probably the bug.
-- Scott
More information about the users
mailing list