Ex: Re: OIDC attribute ("claim") release best practices

Paul B. Henson henson at cpp.edu
Wed Nov 15 00:46:19 UTC 2023


> From: Cantor, Scott
> Sent: Tuesday, November 14, 2023 12:20 PM
> 
> For myself, I advocate one default ruleset for all clients, because in reality
> what everyone wants is the same old stuff that's not terribly worth agitating
> over, name, email, identifier

Our security group considers the campus numeric identifier (yes, the one printed on ID cards) "confidential data". I will say no more...

> Eventually I imagine all of us applying SAML metadata to OIDC will be sent to
> OAuth prison or something.

Thanks, that was an unexpected laugh. Fortunately, I imagine OAuth prison will have a window whose bars were inadvertently made of cardboard tubes ;).


More information about the users mailing list