proposal/discussion: OAuth - (for 1st party usage) only used (by the client) communication options must be allowed by authorization server #1964
Labels
1) Discussion ongoing
Issue is opened and assigned but no clear proposal yet
V51
Group issues related to OAuth
_5.0 - prep
This needs to be addressed to prepare 5.0
spin-off from #1916 "Discussion/Proposal 2"
For a situation, where OAuth is used as a "first-party" authorization solution and the application needs one and only way how it communicates with the authorization server, then for the OAuth client must be configured and the Authorization Server must validate, that: only the expected values are allowed, that is implemented by the client:
offline_access
may be worth special mentionedit: scope in mind - authorization request from OAuth Client to OAuth Authorization Server
--
Feedback from @tghosth in #1916 (comment)
--
Overlap by recommendation from @TobiasAhnoff in #1925
Although response_type and response_mode are not directly privilege, those are all related with allowed flow.
The text was updated successfully, but these errors were encountered: