good first issuepriority: medium
Repository metrics
- Stars
- (100 stars)
- PR merge metrics
- (PR metrics pending)
Description
Description Add support for the OAuth 2.0/OpenID Connect request_uri parameter to allow clients to pass a URI referencing a signed request object during authorization. This enables improved security and flexibility by offloading large request parameters from the authorization request itself.
User Story: As a client application developer, I want to use the request_uri parameter during authorization requests, So that I can securely reference pre-registered request objects without sending all parameters directly.
Acceptance Criteria:
- Implement support for
request_urias defined in OAuth 2.0 and OpenID Connect specifications. - Validate and fetch the request object from the provided URI.
- Verify signatures and integrity of the request object.
- Integrate the request object parameters into the authorization flow seamlessly.
- Handle errors gracefully if the request URI is invalid or inaccessible.
- Document usage of request_uri support for client developers.