Authenticating with OAuth2?
Wessel, Keith
kwessel at illinois.edu
Thu May 30 20:24:57 UTC 2024
Thanks, Scott. Sorry, I misunderstood from your previous email. Thought you were referring to the bug that Henri fixed, but it sounds like you're referring to a buggy client library from this customer.
I was hoping I could go back and tell him that scope is, in fact, required. But I checked RFC 6749 and, in fact, scope is optional for Oauth2 authorizations.
Unless you can think of a workaround, I'll just tell him he either needs to find a way to pass in a scope or switch to SAML, or he can wait for the fix that Henri made to come to our IdP.
Keith
-----Original Message-----
From: Cantor, Scott <cantor.2 at osu.edu>
Sent: Thursday, May 30, 2024 1:49 PM
To: Shib Users <users at shibboleth.net>
Cc: Wessel, Keith <kwessel at illinois.edu>
Subject: Re: Authenticating with OAuth2?
My overall point I guess was that if I'm not off base about this, I think any OAuth library that can't request a scope is not really compliant. That's not an OpenID-specific thing.
And where there's one bad bug, there are more, so I wouldn't likely trust that library to be viable, whatever it is.
-- Scott
More information about the users
mailing list