Skip to content

Conversation

@chriskapp
Copy link
Member

@chriskapp chriskapp commented Jun 2, 2025

Currently the ClientCredentialsDecorator send the client_id and client_secret in the Body, this does not strictly follow the OAuth2 spec s. https://datatracker.ietf.org/doc/html/rfc6749#section-4.4.2 since we need to send the client_id and client_secret also as Basic-Auth header.

…tion header and remove the credentials from the request body
@chriskapp chriskapp self-assigned this Jun 2, 2025
@chriskapp chriskapp changed the base branch from 1.x to master June 2, 2025 15:34
@chriskapp chriskapp linked an issue Jun 2, 2025 that may be closed by this pull request
Co-authored-by: Marc Reichel <marc.reichel@artemeon.de>
@chriskapp chriskapp requested a review from marcreichel June 3, 2025 13:41
@chriskapp chriskapp merged commit e9b72ad into master Jun 4, 2025
3 checks passed
@chriskapp chriskapp deleted the feat/#22-strict-oauth2-decorator branch June 4, 2025 07:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OAuth2 decorator client credentials

4 participants