Skip to content

Conversation

@jogu
Copy link
Member

@jogu jogu commented Feb 18, 2022

Mainly this means creating a copy of the existing endpoint, changing the scope it expects (to one that has the fapi2 attribute) and adding DPoP support (meaning both TLS certificate bound access tokens and DPoP proofs are acceptable for sender constraining the access token).

jogu and others added 3 commits February 15, 2022 13:58
Mainly this means creating a copy of the existing endpoint, changing the scope it uses (to one that has the fapi2 attribute) and adding DPoP support.
Now that Henrik has set the apache reverse proxy to include the X-Forwarded-Proto header and set the java-oauth-server container command line arguments to enable /usr/local/jetty/etc/jetty-http-forwarded.xml the http->https hack is no longer necessary.
@jogu jogu merged commit 6a7a30a into master Mar 4, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants