From: Krzysztof B. <kb...@un...> - 2022-03-08 14:59:52
|
Hi, W dniu 08.03.2022 o 15:48, Marcus Hardt pisze: > Hi There, > > one note on this: > > if there is only a `scopes`, and no `scopes_at` in the request, one could > default to putting the same scopes into the AT and in the userinfo. I > think then it's least painful to introduce this. Well, only governed by endpoint config option "by default put all claims in JWT AT". We won't turn that on for everybody after an update, as we may run into problems in setups which relay on small AT (as your ;). KB |