[Openid-specs-mobile-profile] Issues #1 and #31
Joerg.Connotte at telekom.de
Joerg.Connotte at telekom.de
Thu Jun 15 09:23:06 UTC 2017
Hi guys,
There are two issues remaining that we should decide about in the next call.
Issue #1 Context - Service provider wants to influence message on the device
Gonza’s an my option is to at least move this issue from authentication to user questioning.
Issue #31 how to react if login_hint AND login_hint_token are provided
There are two ways to address this situation
· login_hint_token takes precedence over login_hint, thus login_hint is ignored.
· Throw an invalid_request error as there is potential for either sloppy implementation on the RP side or some corruption in the protocol.
Regards
Jörg
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-mobile-profile/attachments/20170615/0549df5a/attachment-0001.html>
More information about the Openid-specs-mobile-profile
mailing list