Skip to content

Distinguishable client_id when supporting both pre-registered and unregistered clients #47769

@tnorimat

Description

@tnorimat

Description

According to 6.9. Supporting Both Pre-Registered and Unregistered Clients, ASs SHOULD ensure that the client_id strings it generates do not start with https://.

Value Proposition

It hardens keycloak CIMD support's security.

Goals

Making sure that the client_id of registered client by the way of other than CIMD does not start with https://.

Non-Goals

N/A

Discussion

No response

Notes

No response

Metadata

Metadata

Assignees

Labels

No fields configured for enhancement.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions