Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

UAA should publish Authorization Server Metadata, RFC 8414 #3293

Open
strehle opened this issue Feb 13, 2025 · 2 comments
Open

UAA should publish Authorization Server Metadata, RFC 8414 #3293

strehle opened this issue Feb 13, 2025 · 2 comments

Comments

@strehle
Copy link
Member

strehle commented Feb 13, 2025

UAA acts as OAuth2 authorization server and OIDC one.
For OIDC we publish well-knonw -> UAA/.well-known/openid-configuration

But UAA should also publish "/.well-known/oauth-authorization-server"

https://datatracker.ietf.org/doc/html/rfc8414

@strehle
Copy link
Member Author

strehle commented Feb 13, 2025

@Kehrlann FYI , wdyt ?

@Kehrlann
Copy link
Contributor

@strehle Unless our customers require it, I don't think this is high priority:

  • Spring uses it as a backup if openid-configuration is not available
  • Some major players do not publish it, they only publish openid-configuration (e.g. Microsoft and Google do not publish it, only openid-configuration)

Since we already have oidc, it should be good enough in most use-cases.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Development

No branches or pull requests

2 participants