Uploaded image for project: 'Keycloak'
  1. Keycloak
  2. KEYCLOAK-8483

aud includes RP

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • 4.6.0.Final
    • None
    • None
    • Keycloak Sprint 14
    • 2
    • NEW
    • NEW

    Description

      The aud claim should not include the RP by default. The access token aud should only contain services.

      In cases the RP is also providing services and is protected with client roles the RP won't be added by the automatic aud provider, so a separate "Audience" mapper for adding hardcoded audience should be used.

      Attachments

        Issue Links

          Activity

            Public project attachment banner

              context keys: [headless, issue, helper, isAsynchronousRequest, project, action, user]
              current Project key: KEYCLOAK

              People

                mposolda@redhat.com Marek Posolda
                sthorger@redhat.com Stian Thorgersen
                Votes:
                0 Vote for this issue
                Watchers:
                7 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved: