Skip to content

UserInfo Lookup for AccessToken with "AuthType auth-openidc" #1154

Answered by zandbelt
studersi asked this question in Q&A
Discussion options

You must be logged in to vote

no, that is not possible and I would be hesitant to add something like that because it would further blur the line between OAuth 2.0 and OpenID Connect (though granted SPAs with the current implementation are already a mix, hence the separate mod_oauth2 development). I guess the way forward would be to pickup the access token in the application and make your own requests with it, or better, to add the claims you need to the access token introspection result.

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@studersi
Comment options

Answer selected by studersi
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants