FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[Option] Authorization denied for unallowed scopes by peppelinux · Pull Request #85 · IdentityPython/oidcendpoint · GitHub

This repository was archived by the owner on Jun 12, 2021. It is now read-only.

Repository navigation

[Option] Authorization denied for unallowed scopes - #85

Merged
rohe merged 2 commits into
developfrom
deny_invalid_scopes
Sep 18, 2020
Merged

rohe merged 2 commits into
developfrom
deny_invalid_scopes

Conversation

peppelinux commented Sep 7, 2020 •
edited
Loading

Copy link
Copy Markdown
Member

This PR would introduce something heavy but, in some case, useful.
Which those present some faulty RP/Client/RS where the token were not succesfully checked against the scopes for which the token was release for.

The option deny_unknown_scopes force the Authz endpoint (both OAuth2 and OIDC) to return a invalid_scope error message, with http status 400.

Configuration can be made as follow

op:
  server_info:
    issuer: *base_url
    httpc_params:
      verify: False
    session_key:
      filename: data/oidc_op/private/session_jwks.json
      type: OCT
      use: sig
    capabilities:
      # indicates that unknow/unavailable scopes requested by a RP
      # would get a 400 error message instead of be declined implicitly.
      # If False the op will only release the available scopes and ignoring the missings.
      # Default to False
      deny_unknown_scopes: true

This PR is a WiP that follows #73

peppelinux changed the title Authorization denied for unallowed scopes [Option] Authorization denied for unallowed scopes Sep 16, 2020
rohe merged commit bd92a01 into develop Sep 18, 2020

rohe commented Sep 18, 2020

Copy link
Copy Markdown
Contributor

Fine

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL