Record whether clients should advertise id_token in IdP metadata

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Unresolved
    • Priority: Major - P3
    • None
    • Affects Version/s: None
    • Component/s: None
    • None
    • Server Security
    • v8.2, v8.1, v8.0, v7.3, v7.2, v7.0
    • Security 2024-01-08, Security 2024-01-22
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Some IdPs can't issue JWT formatted access tokens, and must issue opaque blobs. Clients of these authorization servers must acquire an id_token to forward to MongoDB Server. We should advertise metadata about these IdPs, so that clients will know that we want the id_token, not the access token. This metadata is only relevant for workforce identity flows. This metadata should default to requesting access tokens.

            Assignee:
            [DO NOT USE] Backlog - Security Team
            Reporter:
            Spencer Jackson
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated: