Skip to content

Support OAuth access tokens without audience claims - #668

Draft
jakeichikawasalesforce wants to merge 5 commits into
masterfrom
oauth-access-token-validation
Draft

jakeichikawasalesforce wants to merge 5 commits into
masterfrom
oauth-access-token-validation

Conversation

@jakeichikawasalesforce

Copy link
Copy Markdown
Collaborator
  • Accept OAuth access tokens without aud when required or endpoint scopes provide the authorization boundary.
  • Preserve audience validation when TABPY_OAUTH_AUDIENCE is configured.
  • Add an opt-in override for trusted non-public JWKS endpoints.
  • Clarify required and endpoint scopes on /info and the landing page.
  • Bump TabPy to 2.16.0 and update documentation.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant