Details
-
Bug
-
Resolution: Done
-
Major
-
None
-
None
-
Keycloak Sprint 14
-
2
-
NEW
-
NEW
Description
The aud claim should not include the RP by default. The access token aud should only contain services.
In cases the RP is also providing services and is protected with client roles the RP won't be added by the automatic aud provider, so a separate "Audience" mapper for adding hardcoded audience should be used.
Attachments
Issue Links
- causes
-
KEYCLOAK-8954 client_id not in aud when using keycloak gatekeeper
-
- Closed
-
- is related to
-
KEYCLOAK-8641 aud included in the authorization tickets
-
- Closed
-