-
I've had an interesting experience trying to support integration with an open source IdP called Authentik (https://github.com/goauthentik/authentik) using openid-client v5.4.3. Implementing the authorization code flow, using PKCE, and NOT providing a
Would it be reasonable for openid-client to consider Related:
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
This is an interesting edge case. I am of the opinion that when the client expects no state to be echoed by the AS there's no |
Beta Was this translation helpful? Give feedback.
This is an interesting edge case. I am of the opinion that when the client expects no state to be echoed by the AS there's no
state
in the query string, I think that's clear based on the implementation.