3 ms·
According to spec, when someone uses oauth to try and log into an existing account for the first time, you must require the user to login through their normal m
by swid 2y ago
According to spec, when someone uses oauth to try and log into an existing account for the first time, you must require the user to login through their normal method and then prompt them to link the login account.
However, the identity provider cannot force you to do that, and there are many examples of apps which do not follow this part of the spec.
- tnzk 2y agoCurious, which part in RFC 6749 do you refer to or other ones?
- swid 2y agoI could have sworn I have seen this in the past, but I am not sure exactly where. Thinking about it; it probably would have been part of OIDC and not directly addressed by OAuth... maybe someone can find it for me, or maybe I misspoke when I said it was part of the spec.
- hirsin 2y agoI could believe that being in 2.1 as a BCP,but if it's not it's a good idea to add it.
- deleted 2y ago[deleted]
- tnzk 2y agoI've checked 2.0 Security BCP, 2.1 draft and OIDC and none of them seemed to cover that. Perhaps I could be in ongoing discussion in the mailing list of 2.1? I only checked their GitHub issues and found nothing relevant.