Moving an OIDC client to PKCE
Wessel, Keith
kwessel at illinois.edu
Thu Feb 13 19:19:21 UTC 2025
Presumably, Peter, if the app switched to a new client ID that was configured on the IdP for PKCE, users would have to log in again. Any access token or refresh token that it had from before the upgrade would have been issued to the old client ID and thus no longer valid. The app developers would like to avoid making everyone reauthenticate if possible.
Keith
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Peter Schober via users
Sent: Thursday, February 13, 2025 12:12 PM
To: users at shibboleth.net
Cc: Peter Schober <peter.schober at univie.ac.at>
Subject: Re: Moving an OIDC client to PKCE
Wessel, Keith via users <users at shibboleth.net> [2025-02-13 18:59 CET]:
> As a transition, is there a way to allow a given client to use
> standard token-based auth _or_ PKCE? The idea would be to allow both
> methods, let the app developer push out a new version of the app
> that switches to PKCE, then after a sufficient amount of time for
> users to update to the new app version, begin forcing PKCE.
How's that different from enforcing the new settings for the new
client_id and once a new version of the "app" is pushed out it would
start using the new client_id and hence the new settings?
(I'm probably missing something.)
Best,
-peter
--
For Consortium Member technical support, see https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!DZ3fjg!6bkS-Towm_2V8EQeTxDyMx0OFj3vjMyOWd1kD3pngbDA7_hRpf3v52pPprSHY8NjVSC2DMfGKdQYjhXnsJX3$
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list