OIDC Client Secret Resolution with Hashed Secret
Cantor, Scott
cantor.2 at osu.edu
Tue May 9 18:29:59 UTC 2023
> I will look into it if that is the better way to go, appreciate the advice, thanks.
Much simpler, more flexible, no need to mess with the metadata, I would advise that. It doesn't work with dynamic registration but of course neither does what you were pursuing.
https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/2929033287/OAuth2ClientAuthnConfiguration
We are not yet at the "no need for registration or metadata at all" stage, that will come later on once we have a simpler way to validate the response locations CAS-style with a regex.
-- Scott
More information about the users
mailing list