
I'm not so sure that this is the right place to ask, but I'm wondering
whether it is correct or not that the following non-normative example found
in "5. Definitions of Multi-Valued Response Type Combinations
in "OAuth 2.0 Multiple Response Type Encoding Practices
<http://openid.net/specs/oauth-v2-multiple-response-types-1_0.html>" does
not include "scope=openid".

  GET /authorize?
    &state=af0ifjsldkj HTTP/1.1
  Host: server.example.com

The reason I'm wondering is that " Authentication Request
in "OpenID Connect Core 1.0
<http://openid.net/specs/openid-connect-core-1_0.html>" requires
Authentication Requests be made as defined in " Authentication
Request <http://openid.net/specs/openid-connect-core-1_0.html#AuthRequest>"
and "" requires the scope request parameter contain openid.

Best Regards,
Takahiko Kawasaki
OAuth mailing list

Reply via email to