-
Notifications
You must be signed in to change notification settings - Fork 13
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[GAIN-POC] prompt and acr_values in the authz request should be optional - default applied #162
Comments
At the same way the parameter "prompt" it should be optional and the IDP should act with its defaults if the RP omits that |
In SPID acr_values and prompt are mandatory, see LL.GG. OIDC SPID |
That's why I am suggesting to not have them mandatory and the idp should define their default |
^ @AntonioFlorio @agcolella @nunzionapoli |
These claims are very important for interoperability with different systems/federation outside the italy. I tag this issue with |
FYI 1OpenID Connect Dynamic Client Registration 1.0 defines the
FYI 2OAuth 2.0 Step-up Authentication Challenge Protocol recommends that an ACR request by the See "Unmet Authentication Requirements for Step-up Authentication" for details. |
May we say that the RP is not forced having acr_values in the request, and the OP SHOULD adopt its most secure or its default?
In other words, I'd say that the OP adopts its default if the RP doesn't request for some specific acr_values
do you agree?
In the current specs it is not clear which parameters are mandatory and which are optional
The text was updated successfully, but these errors were encountered: