Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Recommend usage of PKCE in the README #1227

Closed
gaeljw opened this issue Jan 8, 2025 · 0 comments · Fixed by #1240
Closed

Recommend usage of PKCE in the README #1227

gaeljw opened this issue Jan 8, 2025 · 0 comments · Fixed by #1240
Labels
question Further information is requested

Comments

@gaeljw
Copy link

gaeljw commented Jan 8, 2025

Hello folks,

It seems that PKCE is almost always enabled by default nowadays on OIDC provider side. Even if PKCE is not forced on the server side for the client, it is used if possible (possible = the metadata exposed by the provider say so and the client is compatible).

Then, shouldn't the documentation of kubelogin be updated to reflect that the most of the time the client-secret is not required?

And maybe add a section "what if I cannot use PKCE?" that gives an example with the client-secret.

And/or mention the usage of --oidc-use-pkce that forces PKCE.

Related to:

@gaeljw gaeljw added the question Further information is requested label Jan 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant