Skip to content

Added mandatory support of prompt=login#8

Open
deansaxe wants to merge 3 commits intomainfrom
deansaxe-prompt-login
Open

Added mandatory support of prompt=login#8
deansaxe wants to merge 3 commits intomainfrom
deansaxe-prompt-login

Conversation

@deansaxe
Copy link
Contributor

Following discussion on July 15, 2025 IPSIE call, new language has been added to require support for prompt=login. Related to openid/ipsie#92.

Following discussion on July 15, 2025 IPSIE call, new language has been added to require support for `prompt=login`.
@deansaxe deansaxe self-assigned this Jul 15, 2025
@deansaxe deansaxe requested a review from aaronpk as a code owner July 15, 2025 17:18
@deansaxe
Copy link
Contributor Author

@deansaxe to review https://openid.net/specs/openid-connect-rpinitiated-1_0.html and update the wording if necessary to accommodate sessions.

@deansaxe
Copy link
Contributor Author

Is there any expectation that the IdP session identifier remains static on reauthentication? (See notes from July 22 2025 meeting.)

@deansaxe
Copy link
Contributor Author

deansaxe commented Aug 4, 2025

Following the July 22, 2025 meeting, I took an action item to look at https://openid.net/specs/openid-connect-session-1_0.html (OIDC Session Management) and https://openid.net/specs/openid-connect-rpinitiated-1_0.html (OIDC RP Initiated Logout) to see if there are any relevant details that need to be pulled into IPSIE OIDC SL1.

There are a few different issues to consider here, session management and the ability of the RP to force logout. I don't believe that IPSIE has considered session management at SL1 beyond, "Application-specific session lifetime MUST be set from the assertion" (see https://github.com/openid/ipsie/blob/main/ipsie-levels.md). SL1 does not include any provisions for OP or RP initiated logout, however, these are included at SL2/3.

As a WG, we need to determine whether session management for the identity service is included at SL1. In the absence of a requirement for session management at SL1, I do not believe there are further actions to take on this PR. As always, if you feel differently, please let me know so we can find the path forward.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants