Comments (3)
Also, there's a client type missing in the implementation (Section 2.1):
"The authorization server SHOULD NOT make assumptions about the client type."
As I have noticed this bundle is partly based on a outdated client-side implementation of OAuth2, which on it's part is based on the OAuth2 draft version 10. This version of the documentation does not seem to reckon the definition of a client_type.
Of course, developers may implement these changes themselves, but they might need to be notified if they wish to be fully compatible with the official protocol requirements.
from fosoauthserverbundle.
This bundle only implements the server side of OAuth, not the client side
from fosoauthserverbundle.
I'm aware of that, but the client_type should be registered server-side. Like Facebook's web/native option. According to the documentation it's required to determine a client's trustworthiness and decide whether to use different approaches.
I could be wrong and I have no clue how much of an impact it would be if I would be right... But if I am wrong, I'd really love some clearance on the subject :S
My apologies, the error_response was correct. I had not tested it correctly. (Removed it from my comment)
from fosoauthserverbundle.
Related Issues (20)
- Question about fos_auth_server.yaml
- Security fix for FriendsOfSymfony/oauth2-php HOT 2
- Time for a new release ? HOT 8
- PHP8 support HOT 2
- How to get OAuthToken instead of UserPasswordToken?
- How to add a custom Authentication Provider
- 2.0 timeline and next tagged release? HOT 1
- Suggested way to handle deactivated users
- With symfony 4.4 I'm getting Argument 1 passed to FOS\OAuthServerBundle\Entity\ClientManager::__construct() must be an instance of Doctrine\Common\Persistence\ObjectManager HOT 1
- OAuthToken with null user is not authenticated anymore since symfony 5.4 HOT 5
- PHP 8 Deprecated on getAlias Method HOT 1
- Symfony 6.0 compatibility HOT 6
- PKCE flow support?
- Errors found when auto_mapping is disabled and I didn't heed the instructions about mappings
- SF4 mongodb not finding odm HOT 2
- Officially deprecate the package HOT 5
- Getting attribute 'fieldName': The attribute 'fieldName' is not all !! owed. HOT 3
- PHP 81 Compatibility HOT 2
- Symfony 6 HOT 1
- OAuthStorage still uses EncoderFactoryInterface
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from fosoauthserverbundle.