Google OpenID Connect: Receiving a 500 error when supplying the “max_age” parameter to an authentication request

前端 未结 2 656
没有蜡笔的小新
没有蜡笔的小新 2021-01-17 01:20

As required by Google, we are attempting to finish our migration from Google\'s previous OpenID Authentication flow to the new OpenID Connect implementation. Everything has

2条回答
  •  予麋鹿
    予麋鹿 (楼主)
    2021-01-17 01:58

    As of this week, Google accepts the max_age parameter, and will return an auth_time claim in the ID Token when max_age is passed.

    However, regardless of the value of max_time parameter, users won't be prompted to reauthenticate based on their session time, as that is not a pattern Google supports. Rather, users are asked to reauthenticate only when it is deemed necessary (e.g. the user is accessing their account from a new location).

    If you need to reauthenticate users on your own site, you are encouraged to do so via another means.

提交回复
热议问题