Uploaded image for project: 'AMQ Streams'
  1. AMQ Streams
  2. ENTMQST-1777

[oauth] Support authorization servers with overly simple introspection endpoints

    XMLWordPrintable

Details

    • Task
    • Resolution: Done
    • Major
    • 1.5.0.GA
    • 1.3.0.GA
    • security
    • None

    Description

      OAuth 2.0 only requires introspection endpoint to return whether a token is active or not. Other information necessary to establish user's identity during authentication, or token suitability (claims like sub, username, iss) are optional.

      For these servers an OpenID Connect /userinfo endpoint could be used to gather the additional info during token validation.

      Attachments

        Activity

          People

            Unassigned Unassigned
            marko.strukelj@gmail.com Marko Strukelj
            Jakub Stejskal Jakub Stejskal
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: