3 ms·
OIDC actually already handles this by requiring the `sub` claim to never be re-assigned and unique: https://openid.net/specs/openid-connect-core-1_0.html#IDToke
by brewmarche 3y ago
OIDC actually already handles this by requiring the `sub` claim to never be re-assigned and unique: https://openid.net/specs/openid-connect-core-1_0.html#IDToken https://openid.net/specs/openid-connect-core-1_0.html#IDToke...
Of course this means that an ID token should not contain an e-mail address under `sub`.
- fauigerzigerk 3y agoSo the identity provider could just generate this unchangable ID and let the user link any number of aliases to it, right?
- uxp8u61q 3y agoThat is what TFA suggests, yes.