Unsolicited SSO handler for OIDC?
Cantor, Scott
cantor.2 at osu.edu
Wed Nov 20 13:28:23 UTC 2024
> On the IPSIE OIDF WG call today, the claim was made that
> IdP initiated OIDC logins are supported.
There's literally no such thing in either protocol, the only thiing that can "initiate" is the browser.
The issue is what the request protocol is. In SAML, it's unspecified how to get an IdP to respond in any way but an AuthnRequest, and yet required that every IdP support an unspecified means to do so.
In OIDC, any client can easily create a request message. Whether an RP will accept the response is a different question.
-- Scott
More information about the users
mailing list