-
Notifications
You must be signed in to change notification settings - Fork 22
Open
Labels
confirmedBug has been confirmed, or feature is on the roadmap.Bug has been confirmed, or feature is on the roadmap.featureNew feature or requestNew feature or requestgood first issueGood for newcomersGood for newcomers
Description
Most OIDC clients support PKCE (rfc7636) for the OIDC authentication. It not only allows for secret-less auth (which would be required if we wanted to authenticate the client application directly) but also strengthens the auth provided by the server.
Almost every single modern ODIC Provider supports PKCE and some even enforce it as a standard (such as kanidm) so there is really no downside, only additional security
Metadata
Metadata
Assignees
Labels
confirmedBug has been confirmed, or feature is on the roadmap.Bug has been confirmed, or feature is on the roadmap.featureNew feature or requestNew feature or requestgood first issueGood for newcomersGood for newcomers
Type
Projects
Status
No status