[Openid-specs-mobile-profile] Issue #92: update/fix ID Token examples in CIBA Authentication Results (openid/mobile)

Brian Campbell issues-reply at bitbucket.org
Mon Oct 1 19:45:59 UTC 2018


New issue 92: update/fix ID Token examples in CIBA Authentication Results
https://bitbucket.org/openid/mobile/issues/92/update-fix-id-token-examples-in-ciba

Brian Campbell:

The ID Token in the first example of CIBA 10.3. Push Callback / 10.3.1. Successful Token Delivery is missing the *_hash and auth_req_id claims that the text a few paragraphs below says must be there. It also has nonce, which shouldn't be there. And it should probably match up with the decoded claims in the example below. Also the refresh_token and access_token values really should be longer (and then the *_hash values redone) and if changes are being made in this area then may as well do that too.

The ID Token in the first example of CIBA 10.1.1. Successful Token Response has nonce, which shouldn't be there.

Responsible: b_c


More information about the Openid-specs-mobile-profile mailing list