Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-3967

OAuth Tokens need to be able to keep the end-user name used to authorize the client request

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.5
    • 2.5.1
    • JAX-RS
    • None
    • Unknown

    Description

      Glen helped to identify a limitation to do with OAuth tokens not being able to provide a hint re which end user authorized a client request. This makes it tricky to avoid writing OAuth apps where the end user does not wish to share the same login name between third-party services and resource servers

      Attachments

        Activity

          People

            sergey_beryozkin Sergey Beryozkin
            sergey_beryozkin Sergey Beryozkin
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: