SURFnet / surf-token-based-access

1 stars 1 forks source link

Which scope to return to Client in Resource Registration API based flow #45

Closed michielbdejong closed 2 weeks ago

michielbdejong commented 2 months ago

When using the Resource Registration API of poc-3 instead of the RH-API of poc-2, it might feel appropriate to return the ID of the minted/selected Protected Resource as a scope parameter in the redirect back to the Client. But then. again, why not leave this to either out-of-band configuration or the Scope Info endpoint?