You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Entity Statement JWTs MUST be explicitly typed, by setting the typ header parameter to entity-statement+jwt. This prevents cross-JWT confusion (see [[RFC8725](https://openid.net/specs/openid-connect-federation-1_0.html#RFC8725)], section 3.11).
Please discard the issue if is this is a problem within the SPID specification.
The text was updated successfully, but these errors were encountered:
As per title, the JWT returned from
.well-known/openid-federation
lacks thetyp
header.The example from https://docs.italia.it/italia/spid/spid-cie-oidc-docs/it/versione-corrente/esempi.html#en-1-1-entity-configuration-response-relying-party describes an header such as
while here the response is
Although these examples are "non normativi", oidc-fed as per draft29 is more strict.
(https://openid.net/specs/openid-connect-federation-1_0.html#name-federation-entity-configurat and https://openid.net/specs/openid-connect-federation-1_0.html#entity-statement)
Please discard the issue if is this is a problem within the SPID specification.
The text was updated successfully, but these errors were encountered: