Conversation
d0e6bee to
bfd4f8b
Compare
|
@ctriant please resolve the conflicts. |
rohe
left a comment
There was a problem hiding this comment.
We already have class and function in the configuration. Do we really need a third - callable ??
|
I know |
|
this feature it's something we've discussed with @c00kiemon5ter and we decided to follow the same methodology as with token exchange and token revocation. I don't mind if we refactor or even discard it. What's your opinion on that @c00kiemon5ter ? |
|
What we need is a way to run a custom hook when the userinfo endpoint is invoked. The immediate goal is to enrich the userinfo response with more data fetched by another remote URL, when a certain scope has been given to the access token. The idea is to have this as an additional policy to the userinfo behaviour - the intention is not to modify the behaviour of the userinfo handler. |
|
I have nothing against custom hooks. I just think that having basically two variants of hooks should be enough. |
Signed-off-by: Kostis Triantafyllakis <kostastriantaf@gmail.com>
b89c3a2 to
981dc40
Compare
This PR adds the ability to configure a hook method on the userinfo endpoint configuration to apply policy on the generation of userinfo response.