Ex: Re: OIDC attribute ("claim") release best practices
Paul B. Henson
henson at cpp.edu
Wed Nov 15 00:46:19 UTC 2023
> From: Cantor, Scott
> Sent: Tuesday, November 14, 2023 12:20 PM
>
> For myself, I advocate one default ruleset for all clients, because in reality
> what everyone wants is the same old stuff that's not terribly worth agitating
> over, name, email, identifier
Our security group considers the campus numeric identifier (yes, the one printed on ID cards) "confidential data". I will say no more...
> Eventually I imagine all of us applying SAML metadata to OIDC will be sent to
> OAuth prison or something.
Thanks, that was an unexpected laugh. Fortunately, I imagine OAuth prison will have a window whose bars were inadvertently made of cardboard tubes ;).
More information about the users
mailing list