Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DM-42384: Issue oidc tokens for OIDC access tokens #963

Merged
merged 1 commit into from
Feb 14, 2024
Merged

Conversation

rra
Copy link
Member

@rra rra commented Feb 14, 2024

Instead of setting the access token for OpenID Connect authentications to the same as the ID token, issue a new Gafaelfawr token of the oidc type with no scopes. Change the userinfo endpoint to expect that token instead.

This means that the access token will be automatically revoked if the authentication token used to authenticate the OpenID Connect login is revoked.

Instead of setting the access token for OpenID Connect authentications
to the same as the ID token, issue a new Gafaelfawr token of the
oidc type with no scopes. Change the userinfo endpoint to expect that
token instead.

This means that the access token will be automatically revoked if
the authentication token used to authenticate the OpenID Connect
login is revoked.
@rra rra merged commit 82bda08 into main Feb 14, 2024
5 checks passed
@rra rra deleted the tickets/DM-42384a branch February 14, 2024 03:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant