Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Improved consent handling in token exchange (OIDC to OIDC Client) #31797

@cgeorgilakis

Description

@cgeorgilakis

Description

For OIDC to OIDC Client token exchange, Keycloak ask for user consent based on target client.
However, token exchange is not a browser flow. So, user can not give any extra consent and 'INVALID_CLIENT' error maybe returned.
So, we propose to remove consent asked in token exchange.

We want clients executing token exchange to request consent in other OAuth flows. So, it is not a solution to disable consent in these clients.

Discussion

No response

Motivation

No response

Details

No response

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions