[Openid-specs-ab] Issue #989: Core - Should Userinfo include the issuer? (openid/connect)

Nat Sakimura sakimura at gmail.com
Thu Feb 4 23:41:34 UTC 2016


Right. At the same time, though, it is returning "sub" and a "sub" without
"iss" is kind-a ...
It returns the 'iss' in the header when the response is signed, btw.

Nat

2016年2月5日(金) 8:28 Anthony Nadalin <tonynad at microsoft.com>:

> The issue with this is it may not be the actual authoritative source it is
> just the ID Token Issuer
>
> -----Original Message-----
> From: Openid-specs-ab [mailto:openid-specs-ab-bounces at lists.openid.net]
> On Behalf Of Nat Sakimura
> Sent: Thursday, February 4, 2016 3:17 PM
> To: openid-specs-ab at lists.openid.net
> Subject: [Openid-specs-ab] Issue #989: Core - Should Userinfo include the
> issuer? (openid/connect)
>
> New issue 989: Core - Should Userinfo include the issuer?
>
> https://na01.safelinks.protection.outlook.com/?url=https%3a%2f%2fbitbucket.org%2fopenid%2fconnect%2fissues%2f989%2fcore-should-userinfo-include-the-issuer&data=01%7c01%7ctonynad%40microsoft.com%7cefb57717d10044c3c9d608d32db945cc%7c72f988bf86f141af91ab2d7cd011db47%7c1&sdata=ZkZduaP4TufCu36UpC%2bQY30dofRmx%2fNo97xex6VmUV4%3d
>
> Nat Sakimura:
>
> Maybe userinfo response should include the issuer as well?
>
>
> _______________________________________________
> Openid-specs-ab mailing list
> Openid-specs-ab at lists.openid.net
>
> https://na01.safelinks.protection.outlook.com/?url=http%3a%2f%2flists.openid.net%2fmailman%2flistinfo%2fopenid-specs-ab&data=01%7c01%7ctonynad%40microsoft.com%7cefb57717d10044c3c9d608d32db945cc%7c72f988bf86f141af91ab2d7cd011db47%7c1&sdata=Hc2fZfuSwReUEcDQr0CrEKFx1DQNjEJvz6H6IpeuEtw%3d
> _______________________________________________
> Openid-specs-ab mailing list
> Openid-specs-ab at lists.openid.net
> http://lists.openid.net/mailman/listinfo/openid-specs-ab
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20160204/ce0e2279/attachment-0001.html>


More information about the Openid-specs-ab mailing list