From: Sander A. <sa....@fz...> - 2017-12-15 10:00:08
|
Hi Krzysztof, I have a question about Oauth token validation. Let me describe the situation first: We have two services (a and b) which are connected to unity. Both services have its own oauth client. Unity does the authentication for both services. Service b must query information from service a. Service a talk only to authenticated "users". Service b requests an access token from unity with its own oauth client and send the token to service b. Is service a allowed to validate the token by unity and request user information? Or is it no possible because the token was generated for another client? Best regards, Sander -- Federated Systems and Data Juelich Supercomputing Centre phone: +49 2461 61 8847 fax: +49 2461 61 6656 email: sa....@fz... ----------------------------------------------------------------------- ----------------------------------------------------------------------- Forschungszentrum Juelich GmbH 52425 Juelich Sitz der Gesellschaft: Juelich Eingetragen im Handelsregister des Amtsgerichts Dueren Nr. HR B 3498 Vorsitzender des Aufsichtsrats: MinDir Dr. Karl Eugen Huthmacher Geschaeftsfuehrung: Prof. Dr.-Ing. Wolfgang Marquardt (Vorsitzender), Karsten Beneke (stellv. Vorsitzender), Prof. Dr.-Ing. Harald Bolt, Prof. Dr. Sebastian M. Schmidt ----------------------------------------------------------------------- ----------------------------------------------------------------------- |