aacli for oidc op

Cantor, Scott cantor.2 at osu.edu
Fri Oct 6 12:35:23 UTC 2023


It only supports it in a loose/accidental sense. The tool is part of the IdP and the OP is a plugin, so there's no means to extend it to support other protocols.

It should populate the requester with whatever the parameter is, but it can't honor rules based on e.g. OAuth scope and it won't actually support encoding things into JSON in the manner it would for that protocol.

It probably would honor SAML metadata for the requester and apply any filter rules that are based on that, but it wouldn't do that for any other form of metadata.

-- Scott




More information about the users mailing list