Authenticating with OAuth2?
Wessel, Keith
kwessel at illinois.edu
Fri May 31 14:32:14 UTC 2024
Right. But since the OAuth2 spec says scope is optional for OAuth2 authorization requests, I can't really tell him that the library he's using violates the spec. Cuts corners, yes. Is broken, probably since it's already cutting corners. But the lack of a scope is allowed from what I can tell. So, I appreciate that you all are addressing that in the IdP code.
Keith
-----Original Message-----
From: Cantor, Scott <cantor.2 at osu.edu>
Sent: Thursday, May 30, 2024 5:30 PM
To: Shib Users <users at shibboleth.net>
Cc: Wessel, Keith <kwessel at illinois.edu>
Subject: Re: Authenticating with OAuth2?
> Thanks, Scott. Sorry, I misunderstood from your previous
> email. Thought you were referring to the bug that Henri
> fixed, but it sounds like you're referring to a buggy client
> library from this customer.
It's both. We have/had a bug, but so does his library. I was just saying that the idea scope is "only" in OpenID is false.
-- Scott
More information about the users
mailing list