Commit 461546b
committed
fix(client): do not put client_id in the token body under client_secret_basic
RFC 6749 section 2.3 says client credentials should not be in the request
body when they are already in the Authorization header. The basic auth
branch stripped client_secret but left client_id, so strict token endpoints
(Keycloak, Okta in strict mode) reject the request as presenting two auth
methods at once. Drop client_id too, and flip the two basic auth tests plus
the refresh test that asserted the old behavior.
Fixes #31381 parent a4f4ccd commit 461546b
2 files changed
Lines changed: 9 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
262 | 262 | | |
263 | 263 | | |
264 | 264 | | |
265 | | - | |
266 | | - | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
267 | 270 | | |
268 | 271 | | |
269 | 272 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
676 | 676 | | |
677 | 677 | | |
678 | 678 | | |
679 | | - | |
| 679 | + | |
680 | 680 | | |
681 | 681 | | |
682 | | - | |
| 682 | + | |
683 | 683 | | |
684 | 684 | | |
685 | 685 | | |
| |||
712 | 712 | | |
713 | 713 | | |
714 | 714 | | |
715 | | - | |
| 715 | + | |
716 | 716 | | |
717 | 717 | | |
| 718 | + | |
718 | 719 | | |
719 | 720 | | |
720 | 721 | | |
| |||
0 commit comments