[Openid-specs-mobile-profile] [E] Issues #1 and #31

Hjelm, Bjorn Bjorn.Hjelm at VerizonWireless.com
Fri Jun 16 14:07:32 UTC 2017

Welcome back. I’ll add this two items to the agenda for the next call.


From: Openid-specs-mobile-profile [mailto:openid-specs-mobile-profile-bounces at lists.openid.net] On Behalf Of Joerg.Connotte at telekom.de
Sent: Thursday, June 15, 2017 2:23 AM
To: openid-specs-mobile-profile at lists.openid.net
Subject: [E] [Openid-specs-mobile-profile] Issues #1 and #31

Hi guys,

There are two issues remaining that we should decide about in the next call.

Issue #1 Context - Service provider wants to influence message on the device
Gonza’s an my option is to at least move this issue from authentication to user questioning.

Issue #31 how to react if login_hint AND login_hint_token are provided

There are two ways to address this situation

•         login_hint_token takes precedence over login_hint, thus login_hint is ignored.

•         Throw an invalid_request error as there is potential for either sloppy implementation on the RP side or some corruption in the protocol.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-mobile-profile/attachments/20170616/285b05fe/attachment.html>

More information about the Openid-specs-mobile-profile mailing list