Originally submitted by dgtonge (Dave Tonge) on 2019-06-12
We discussed on the call today whether we need ID Tokens in the FAPI profile of CIBA.
They are not needed as a detached signature and so perhaps we should remove the need for them.
The core spec leaves an option open for CIBA to be used without the openid scope, but it would require us to specify some behaviour that is currently inferred or defined in OpenID Connect core (e.g. id_token_hint, etc.)
Bitbucket status: open
Bitbucket origin: issue 229
We discussed on the call today whether we need ID Tokens in the FAPI profile of CIBA.
They are not needed as a detached signature and so perhaps we should remove the need for them.
The core spec leaves an option open for CIBA to be used without the openid scope, but it would require us to specify some behaviour that is currently inferred or defined in OpenID Connect core (e.g. id_token_hint, etc.)
Bitbucket status: open
Bitbucket origin: issue 229