-
There's a line in oidcc_token_introspection.erl:extract_response:
Which seems to mean that the function will only introspect a token that was issued by the client of the caller (i.e. one's own token) or a token issued elsewhere but only to a client_id of the same name.
It would seem that this constraint would just need to be removed to fix the problem. Unless there is another mechanism for validating a token through the AS? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Continued in #364 |
Beta Was this translation helpful? Give feedback.
Continued in #364