<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:12.0pt;
        font-family:"Aptos",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Aptos",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;
        mso-ligatures:none;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word;-webkit-nbsp-mode: space;line-break:after-white-space">
<div class="WordSection1">
<p class="MsoNormal">Thanks, Henri. All excellent questions/points. I’ve passed this along to the vendor.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Keith<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> users <users-bounces@shibboleth.net>
<b>On Behalf Of </b>Henri Mikkonen via users<br>
<b>Sent:</b> Tuesday, June 4, 2024 4:02 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Henri Mikkonen <henri.mikkonen@csc.fi><br>
<b>Subject:</b> Re: Authenticating with OAuth2?<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Hi Keith,<o:p></o:p></p>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Joining the discussion a bit late. One good question for the OAuth2 client would be: how they would like to use it for authentication? In short: pure OAuth2 is about issuing and usage of access token, possibly together with a refresh token.
 The access token is supposed to be used against a protected resource. What would be the protected resource? OIDC standardises the user info endpoint to be the protected resource from which to obtain the user attributes via access token. In addition to that,
 OIDC also specifies the id_token that is used for the authentication metadata, and optionally for the user attributes too.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">This is a good link to be given to anyone who claims that OAuth2 is an authentication protocol: <a href="https://urldefense.com/v3/__https:/oauth.net/articles/authentication/__;!!DZ3fjg!4zttsYjK5Xi_IsboftaY8K_mv6pePf-pkb2YOaLDxcjG1TPCR8u_DiImVaXBHb_XgcxyGBS5kPFt6PSla6R6$">https://oauth.net/articles/authentication/</a> .
 The main message of the article is that it’s not.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Perhaps the client expected you to provide JWT access tokens with some user attributes, but let them read that article.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">BR,<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">Henri.<o:p></o:p></p>
<div>
<p class="MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<p class="MsoNormal">On 31. May 2024, at 19.53, Wessel, Keith via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<o:p></o:p></p>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div>
<p class="MsoNormal">All very valid points. I'm going to pass these along to him. I wasn't actually comfortable with using OAuth2 for this use case, anyway, but I couldn't elaborate why. You put your finger on it.<br>
<br>
Thank you,<br>
Keith<br>
<br>
<br>
-----Original Message-----<br>
From: Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> <br>
Sent: Friday, May 31, 2024 11:30 AM<br>
To: Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
Cc: Wessel, Keith <<a href="mailto:kwessel@illinois.edu">kwessel@illinois.edu</a>><br>
Subject: Re: Authenticating with OAuth2?<br>
<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">Right. But since the OAuth2 spec says scope is optional for<br>
OAuth2 authorization requests, I can't really tell him that the<br>
library he's using violates the spec.<o:p></o:p></p>
</blockquote>
<p class="MsoNormal"><br>
Sorry, but you can. This comes up in SAML a lot. It's important.<br>
<br>
Features may be optional to *use*, but they're mandatory to implement.<br>
<br>
We had a bug, and so does that library.<br>
<br>
In general, scope is really required for OAuth to work safely on its own because scope was originally the substitute for "audience", it limits a token's usage.<br>
<br>
One other point I had intended to make: what he's asking for isn't safe anyway. If you try and abuse OAuth to "just" do SSO, you'll generally have holes. OpenID is at a basic level just intended to codify usage to avoid the worst of them, so without it, you
 tend to end up with problems.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https:/shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!DZ3fjg!4zttsYjK5Xi_IsboftaY8K_mv6pePf-pkb2YOaLDxcjG1TPCR8u_DiImVaXBHb_XgcxyGBS5kPFt6HJHaAXk$">
https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</div>
</div>
</blockquote>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</div>
</body>
</html>