OIDC claims missing after upgrade to IdP 4.1

Cantor, Scott cantor.2 at osu.edu
Wed Jul 21 01:27:58 UTC 2021


On 7/20/21, 9:22 PM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:

> We do use a database for storing consent decisions, but obviously, the consent post authentication flow isn't
> enabled for any of the token or userinfo non-browser profiles. I think I'm missing your point, though, on this.
> Can you explain, please?

There's a setting to encode attributes into the tokens so that they can be recovered without having to resolve them again, and I was thinking maybe that triggered a bug in the consent enforcement.

The tokens can also store the consent decisions I think to allow client side consent storage to work but I really don't know all the options or how they work.

Somewhere in some mix of settings is probably the bug.

-- Scott




More information about the users mailing list