Details
-
Bug
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
oauth2-1.0.0
-
None
Description
JWTClaimsSetParser contains
if (AUDIENCE.equals(key)) { getBuilder().setClaimsSetAudience(String.valueOf(value));
which leads to something like "aud": "[Ljava.lang.Object;@34657d74" when the audience provided by the server is a JSON array - which is the canonical representation and a single string is only the exception according to http://openid.net/specs/openid-connect-core-1_0.html#IDToken