openid-certification / oidctest

THE CERTIFICATION TEST SUITE HAS BEEN MIGRATED TO A NEW SERVICE https://www.certificatinon.openid.net
Other
49 stars 15 forks source link

profile doc & code don't seem in alignment over rp-userinfo-bearer-* #211

Open jogu opened 4 years ago

jogu commented 4 years ago

The profile lists rp-userinfo-bearer-body as an alternative to rp-userinfo-bearer-header:

Screenshot_2019-12-20_at_17 11 14

The test suite (e.g. https://rp.certification.openid.net:8080/list?profile=C ) lists 'header' as mandatory and body as optional.

My suspicion is the profile should list the 'access token in body' test as 'optional' as OPs aren't required to support that form.