<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div dir="ltr">
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 11pt;">
Excellent! Because it is an array, I wanted to create a new entry in the list instead of thinking about “code id_token” as a single-value. We were able to overcome the first <span>hurdle. Thank you!</span><span></span></div>
<div dir="ltr"><br>
</div>
<div id="ms-outlook-mobile-signature">
<div style="page:WordSection1">
<div>
<p style="margin:0in;font-size:11pt;font-family:Aptos, sans-serif"><span><span style="color: black;">--<o:p></o:p></span></span></p>
<p style="margin:0in;font-size:11pt;font-family:Aptos, sans-serif"><span><span style="color: black;">Ryan Rumbaugh</span></span><o:p></o:p></p>
</div>
</div>
</div>
<div id="mail-editor-reference-message-container">
<div class="ms-outlook-mobile-reference-message skipProofing"><span style="mso-bookmark:_MailOriginalBody">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
<div style="font-family: Aptos; font-size: 12pt; text-align: left; border-width: 1pt medium medium; border-style: solid none none; border-color: rgb(181, 196, 223) currentcolor currentcolor; padding: 3pt 0in 0in; color: black;">
<span style="font-weight:bold">From: </span>users <users-bounces@shibboleth.net> on behalf of Henri Mikkonen <henri.mikkonen@nimbleidm.com><br>
<span style="font-weight:bold">Date: </span>Tuesday, November 5, 2024 at 1:09 AM<br>
<span style="font-weight:bold">To: </span>users@shibboleth.net <users@shibboleth.net><br>
<span style="font-weight:bold">Subject: </span>Re: OIDC Response Type Assistance<br>
<br>
</div>
<font size="2"><span style="font-size:11pt;">
<div class="PlainText">Caution: Non-NU Email<br>
<br>
<br>
Hi Ryan,<br>
<br>
The section 3 of OIDC core [1] specification contains a table that<br>
describes how response_type values maps to flows. There you can see that<br>
'code', 'id_token' and 'code id_token' are 3 different values.<br>
<br>
> |WARN<br>
> [net.shibboleth.idp.plugin.oidc.op.oauth2.profile.impl.ValidateResponseType:136] - Profile Action ValidateResponseType: The response type code id_token is not registered for this RP|<br>
<br>
According to the log snippet, your RP seems to be requesting 'code<br>
id_token', but only 'code' and 'id_token' are registered in the metadata.<br>
<br>
BR,<br>
Henri.<br>
<br>
[1] <a href="https://urldefense.com/v3/__https://openid.net/specs/openid-connect-core-1_0.html*Authentication__;Iw!!PvXuogZ4sRB2p-tU!CiDsmSU0aRQgADvQVl7tqVwiTXyobPiNeKLMKop_vymgg8MCeAbHB5axnwtRBtBwuL1wn3i9WPVMz0Fmo09P_2vGXTVpv2S6$">
https://urldefense.com/v3/__https://openid.net/specs/openid-connect-core-1_0.html*Authentication__;Iw!!PvXuogZ4sRB2p-tU!CiDsmSU0aRQgADvQVl7tqVwiTXyobPiNeKLMKop_vymgg8MCeAbHB5axnwtRBtBwuL1wn3i9WPVMz0Fmo09P_2vGXTVpv2S6$</a><br>
--<br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!PvXuogZ4sRB2p-tU!CiDsmSU0aRQgADvQVl7tqVwiTXyobPiNeKLMKop_vymgg8MCeAbHB5axnwtRBtBwuL1wn3i9WPVMz0Fmo09P_2vGXfbqNUi-$">
https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!PvXuogZ4sRB2p-tU!CiDsmSU0aRQgADvQVl7tqVwiTXyobPiNeKLMKop_vymgg8MCeAbHB5axnwtRBtBwuL1wn3i9WPVMz0Fmo09P_2vGXfbqNUi-$</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></span></div>
</div>
</div>
</body>
</html>