OIDC OP 3.4 and issueIdTokenViaRefreshToken

Cantor, Scott cantor.2 at osu.edu
Wed Aug 2 16:06:34 UTC 2023


> Consider documenting on the wiki that, if slackers like me who haven't yet
> enabled the token profile are wondering why their responses don't include
> the ID token when using a refresh token, the implicit default for that setting
> is false.

I think the better question is why anybody would notice. The ID token was defined to be about the initial hackery that they used to layer SSO on OAuth. It really has no business being used anywhere else. I think anything requiring it to be there is pretty much broken itself. The spec specifically says it "might not be there" and it really shouldn't be.

With the imminent move to 4.0 and the ability to break things, I would probably like to see it flipped to a default of false anyway.

-- Scott




More information about the users mailing list