oidc-auth-manager icon indicating copy to clipboard operation
oidc-auth-manager copied to clipboard

issuer URIs with a path part don't work

Open zenomt opened this issue 6 years ago • 0 comments

oidc-auth-mananger seems to make an invalid assumption that all OIDC Issuers are URIs with an empty path part. if a webid has an OIDC Issuer URI with a path part (like my webid https://zenomt.zenomt.com/card.ttl#me with issuer https://zenomt.com/oidc/), it can never be matched against the id_token iss claim because the discovered issuer URI is reduced to its origin before being compared. see these lines in preferred-provider.js.

OIDC Issuers are allowed to have path parts.

zenomt avatar Jul 13 '19 21:07 zenomt