Authenticating with OAuth2?

Wessel, Keith kwessel at illinois.edu
Thu May 30 20:24:57 UTC 2024


Thanks, Scott. Sorry, I misunderstood from your previous email. Thought you were referring to the bug that Henri fixed, but it sounds like you're referring to a buggy client library from this customer.

I was hoping I could go back and tell him that scope is, in fact, required. But I checked RFC 6749 and, in fact, scope is optional for Oauth2 authorizations.

Unless you can think of a workaround, I'll just tell him he either needs to find a way to pass in a scope or switch to SAML, or he can wait for the fix that Henri made to come to our IdP.

Keith


-----Original Message-----
From: Cantor, Scott <cantor.2 at osu.edu> 
Sent: Thursday, May 30, 2024 1:49 PM
To: Shib Users <users at shibboleth.net>
Cc: Wessel, Keith <kwessel at illinois.edu>
Subject: Re: Authenticating with OAuth2?

My overall point I guess was that if I'm not off base about this, I think any OAuth library that can't request a scope is not really compliant. That's not an OpenID-specific thing.

And where there's one bad bug, there are more, so I wouldn't likely trust that library to be viable, whatever it is.

-- Scott




More information about the users mailing list