OIDC Response Type Assistance
Ryan Rumbaugh
rrumbaugh at nebraska.edu
Tue Nov 5 20:42:28 UTC 2024
Excellent! Because it is an array, I wanted to create a new entry in the list instead of thinking about “code id_token” as a single-value. We were able to overcome the first hurdle. Thank you!
--
Ryan Rumbaugh
From: users <users-bounces at shibboleth.net> on behalf of Henri Mikkonen <henri.mikkonen at nimbleidm.com>
Date: Tuesday, November 5, 2024 at 1:09 AM
To: users at shibboleth.net <users at shibboleth.net>
Subject: Re: OIDC Response Type Assistance
Caution: Non-NU Email
Hi Ryan,
The section 3 of OIDC core [1] specification contains a table that
describes how response_type values maps to flows. There you can see that
'code', 'id_token' and 'code id_token' are 3 different values.
> |WARN
> [net.shibboleth.idp.plugin.oidc.op.oauth2.profile.impl.ValidateResponseType:136] - Profile Action ValidateResponseType: The response type code id_token is not registered for this RP|
According to the log snippet, your RP seems to be requesting 'code
id_token', but only 'code' and 'id_token' are registered in the metadata.
BR,
Henri.
[1] https://urldefense.com/v3/__https://openid.net/specs/openid-connect-core-1_0.html*Authentication__;Iw!!PvXuogZ4sRB2p-tU!CiDsmSU0aRQgADvQVl7tqVwiTXyobPiNeKLMKop_vymgg8MCeAbHB5axnwtRBtBwuL1wn3i9WPVMz0Fmo09P_2vGXTVpv2S6$
--
For Consortium Member technical support, see https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!PvXuogZ4sRB2p-tU!CiDsmSU0aRQgADvQVl7tqVwiTXyobPiNeKLMKop_vymgg8MCeAbHB5axnwtRBtBwuL1wn3i9WPVMz0Fmo09P_2vGXfbqNUi-$
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20241105/a5a2c611/attachment.htm>
More information about the users
mailing list