Skip to content

Conversation

jarlandre
Copy link

  1. denying client credentials grant if client is public
  2. adjusting tests to make different clients based on whether or not they are public
  3. this will allow for using public grants like authorisation code flow with client_secret not set on client and Public set to true
  4. if libraries implement this and dont want to care about it they can just return false for IsPublic
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants