erlef / erlef/oidcc

Validation of Aggregated Userinfo Claims

Open
#453 0 comments 0 reactions 0 assignees View on GitHub
bug help wanted
Dominant language
Erlang
Stars
240
Forks
69
Avg merge
10h 40m
Merged PRs (30d)
4

Description

### oidcc version

latest

### Erlang version

any

### Elixir version

any

### Summary

* Certification Suite: `oidcc-client-test-plan`
* Certification Test: `oidcc-client-test-aggregated-claims`

The certification test contains an aggregated JWT Userinfo Claim with an unsigned Token.

### Current behavior

Validation Fails

### How to reproduce

Run `oidcc-client-test-aggregated-claims` test

### Expected behavior

Spec: https://openid.net/specs/openid-connect-core-1_0.html#AggregatedDistributedClaims

> § 5.6.2. Aggregated and Distributed Claims
> ...
> An iss (issuer) Claim SHOULD be included in any JWT issued by a Claims Provider so that the Claims Provider's keys can be retrieved for signature validation of the JWT. The value of the Claim is the Claims Provider's Issuer Identifier URL.
> ...

Based on this i assume:
* Validation is not according to userinfo rules.
* Instead:
* `none` is valid
* If `iss` present, load config / JWKs and validate using the rules of that `iss`.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.