Skip to content

Conversation

fine-pine
Copy link

  • Disallow usage of the openid scope in device authorization requests
  • Allow ID token refresh when an ID token already exists

Closes gh-2037

- Disallow usage of the `openid` scope in device authorization requests
- Allow ID token refresh when an ID token already exists

Closes spring-projectsgh-2037

Signed-off-by: fine-pine <[email protected]>
@fine-pine fine-pine marked this pull request as ready for review August 26, 2025 09:43
Co-authored-by: injae kim <[email protected]>
Signed-off-by: Lee Song Mok <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status: waiting-for-triage An issue we've not yet triaged
Projects
None yet
Development

Successfully merging this pull request may close these issues.

500 Error on Refresh Token Request in Device Code Flow When Using openid Scope
3 participants