Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GAIN-PoC] Authz request - nonce parameter is REQUIRED for SPID and CIE id #163

Open
peppelinux opened this issue Mar 2, 2023 · 0 comments
Labels

Comments

@peppelinux
Copy link
Member

In The authz request the nonce parameter is required to prevent replay attacks using the implicit flow, SPID and CIE id doesnt support the implicit flow.

Using auth code flow the nonce is not required, following OIDC Core that defines it as OPTIONAL.

At the same time, SPID and CIE id are based on OIDC iGov, and this latter defines the nonce parameter in the Authz request as REQUIRED

https://openid.net/specs/openid-igov-openid-connect-1_0-03.html

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant