solid / webid-oidc-spec

WebID-OIDC Authentication Spec v0.1.0
MIT License
56 stars 18 forks source link

OP doesn't have to host WebID #7

Closed elf-pavlik closed 5 years ago

elf-pavlik commented 5 years ago

https://github.com/solid/webid-oidc-spec#pod

A Personal Online Datastore (POD for short). It plays several roles -- firstly, it stores a user's data (and so acts as a Resource Server). In many cases, it also hosts the user's WebID Profile, and implements the API endpoints that allow it to act as a WebID-OIDC Identity Provider (OP).

WebID Profile can specify any OP with solid:oidcIssuer, since WebID Profile has to stay public any RS can host it, it doesn't even require RP if one edits it out of bound and doesn't rely on WAC for that.

elf-pavlik commented 5 years ago

Actually this section makes it pretty clear that OP doesn't have to host WebID: https://github.com/solid/webid-oidc-spec#authorized-oidc-issuer-discovery