Uploaded image for project: 'OpenId Connect'
  1. OpenId Connect
  2. OIDC-180

Allows skipping the userinfo request even in code flow

    XMLWordPrintable

Details

    • New Feature
    • Resolution: Fixed
    • Major
    • 2.9.0
    • 2.8.8
    • Authenticator
    • None
    • Unknown

    Description

      There is a bug in some OIDC provider which are not actually properly implementing the userinfo endpoint. Fortunately, it's also often cases which put user information on the id token, making it possible to just skip the userinfo despite what the response type indicates.

      Attachments

        Activity

          People

            tmortagne Thomas Mortagne
            tmortagne Thomas Mortagne
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: