
28 Dec
2015
28 Dec
'15
5 p.m.
UMA-tarians, We added support in the Gluu Server for local token introspection. A few notes are here: https://github.com/GluuFederation/oxAuth/issues/111 We decided to use the same signing algorithm as was registered for the id_token signing in OpenID Connect dynamic client registration, and re-publish this info in the UMA discovery endpoint. We also added a discovery value "rpt_as_jwt" to specify that local token introspection is in use. Feedback is welcome... are we missing something? - Mike