OIDC OP 3.4 and issueIdTokenViaRefreshToken

Wessel, Keith kwessel at illinois.edu
Wed Aug 2 16:01:37 UTC 2023


Thanks, Scott. I ended up moving all of the properties I had on the OIDC SSO profile to the Oauth2 token profile, OIDC SSO now just has its defaults. Everything's working once again.

Consider documenting on the wiki that, if slackers like me who haven't yet enabled the token profile are wondering why their responses don't include the ID token when using a refresh token, the implicit default for that setting is false. Right now, it just says true as the default on the token profile page which really threw me until you told me the default was profile-specific.

I'd try and make that edit myself, but I'm not sure where it best fits in.

Keith


-----Original Message-----
From: Cantor, Scott <cantor.2 at osu.edu> 
Sent: Tuesday, August 1, 2023 7:55 AM
To: Shib Users <users at shibboleth.net>
Cc: Wessel, Keith <kwessel at illinois.edu>
Subject: Re: OIDC OP 3.4 and issueIdTokenViaRefreshToken

> One question: if I'm overriding things (access token lifetime, ID token
> lifetime, refresh token chain lifetime) for the OIDC SSO profile, do I also
> need to override those for the oauth token profile?

I don't know exactly under what conditions it needs that, I would hope that they would only need to be in one place but that place is not likely to be the front channel profile.

-- Scott




More information about the users mailing list