Skip to content

Issue with generic OIDC provider #3782

Closed Answered by jonas-jonas
shreeharsha-factly asked this question in Q&A
Discussion options

You must be logged in to vote

This is correct. The reason is, that the state parameter is generated by Kratos and should be treated as an opaque token. If your provider does not return the state parameter, that seems like a security issue on the provider's side, as the state parameter is a vital security mechanism of OIDC. See also https://stackoverflow.com/questions/26132066/what-is-the-purpose-of-the-state-parameter-in-oauth-authorization-request

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@jonas-jonas
Comment options

Answer selected by shreeharsha-factly
@shreeharsha-factly
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants