solid / webid-oidc-spec

WebID-OIDC Authentication Spec v0.1.0
MIT License
56 stars 18 forks source link

Machine-readable 401s? #1

Open dan-f opened 7 years ago

dan-f commented 7 years ago

The brief workflow summary states that Alice gets presented with a "sign in" screen with her 401 from bob.com.

In the common case in which Alice's user agent is a mobile app or an async browser request, I'd expect Bob's response to include a WWW-Authenticate header and a JSON payload.