OIDC OP 3.4 and issueIdTokenViaRefreshToken

Wessel, Keith kwessel at illinois.edu
Wed Aug 2 16:13:44 UTC 2023


An excellent point. I'll pass that along to our app developers. A better question is why the IdP ignored the spec and included it in V3.3 and earlier of the plugin. But since we know what the spec states, that's relatively moot at this point.

Keith


-----Original Message-----
From: Cantor, Scott <cantor.2 at osu.edu> 
Sent: Wednesday, August 2, 2023 11:07 AM
To: Shib Users <users at shibboleth.net>
Cc: Wessel, Keith <kwessel at illinois.edu>
Subject: Re: OIDC OP 3.4 and issueIdTokenViaRefreshToken

> Consider documenting on the wiki that, if slackers like me who haven't yet
> enabled the token profile are wondering why their responses don't include
> the ID token when using a refresh token, the implicit default for that setting
> is false.

I think the better question is why anybody would notice. The ID token was defined to be about the initial hackery that they used to layer SSO on OAuth. It really has no business being used anywhere else. I think anything requiring it to be there is pretty much broken itself. The spec specifically says it "might not be there" and it really shouldn't be.

With the imminent move to 4.0 and the ability to break things, I would probably like to see it flipped to a default of false anyway.

-- Scott




More information about the users mailing list