Skip to content
Discussion options

You must be logged in to vote

trusted_audiences is for something different:

https://openid.net/specs/openid-connect-core-1_0.html

3.1.3.7. ID Token Validation
Clients MUST validate the ID Token in the Token Response in the following manner:
[...]
3. The Client MUST validate that the aud (audience) Claim contains its client_id value registered at the Issuer identified by the iss (issuer) Claim as an audience. The aud (audience) Claim MAY contain an array with more than one element. The ID Token MUST be rejected if the ID Token does not list the Client as a valid audience, or if it contains additional audiences not trusted by the Client.

According to this spec, we have to validate that aud does not contain untrusted v…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@maennchen
Comment options

Answer selected by 1player
@1player
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants