Skip to content

Commit

Permalink
Update CAMARA-Security-Interoperability.md
Browse files Browse the repository at this point in the history
addes note on scope
  • Loading branch information
AxelNennker authored Feb 27, 2024
1 parent 269e277 commit debbb2e
Showing 1 changed file with 9 additions and 0 deletions.
9 changes: 9 additions & 0 deletions documentation/CAMARA-Security-Interoperability.md
Original file line number Diff line number Diff line change
Expand Up @@ -160,6 +160,15 @@ The client MUST authenticate with the authorization server as described in [Clie
Scope values determine the specific CAMARA services being requested by the Service Provider, subject to the SP being registered to use those services. The scope values must be documented in the API OAS files by all Camara API subprojects. This document does not change OIDC definitions of scope values.


---
**NOTE**

Scope values are an integral part of any OAuth2 and OIDC implementation. The RS enforces API access based on scope (if the Camara API subproject defines scopes).
Therefore scopes should be available to API implementations.

---


## Missing "openid" scope

[OIDC Core Authentication Request](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest) states the following about the value of scope.
Expand Down

0 comments on commit debbb2e

Please sign in to comment.