Skip to content

Handling of code verification challenge #506

@BalSzabo

Description

@BalSzabo

If the realm level setting "Code verifier parameter required" is not active and the client sends the challenge for code verification the auth server doesn't check the code, but accepts any code challenge. The could be an active check regardless of it is required or not.

This is a realm level setting, we cannot enable it, because not all of our clients support this feature, but some clients would like to use it properly in the same realm.

OpenAM version: 14.6.4

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions