OIDC OP 3.4 and issueIdTokenViaRefreshToken
Wessel, Keith
kwessel at illinois.edu
Wed Aug 2 16:01:37 UTC 2023
Thanks, Scott. I ended up moving all of the properties I had on the OIDC SSO profile to the Oauth2 token profile, OIDC SSO now just has its defaults. Everything's working once again.
Consider documenting on the wiki that, if slackers like me who haven't yet enabled the token profile are wondering why their responses don't include the ID token when using a refresh token, the implicit default for that setting is false. Right now, it just says true as the default on the token profile page which really threw me until you told me the default was profile-specific.
I'd try and make that edit myself, but I'm not sure where it best fits in.
Keith
-----Original Message-----
From: Cantor, Scott <cantor.2 at osu.edu>
Sent: Tuesday, August 1, 2023 7:55 AM
To: Shib Users <users at shibboleth.net>
Cc: Wessel, Keith <kwessel at illinois.edu>
Subject: Re: OIDC OP 3.4 and issueIdTokenViaRefreshToken
> One question: if I'm overriding things (access token lifetime, ID token
> lifetime, refresh token chain lifetime) for the OIDC SSO profile, do I also
> need to override those for the oauth token profile?
I don't know exactly under what conditions it needs that, I would hope that they would only need to be in one place but that place is not likely to be the front channel profile.
-- Scott
More information about the users
mailing list