Skip to content
Discussion options

You must be logged in to vote

@evrys some questions:

  • what are you using to implement your callout?
  • how is the server configured for auth where the user is connecting?

IMHO you need to have the client give you want you want to auth on, don't depend on the server for that.

Also - callout doesn't do any kind of challenge response, you evaluate on what you got from the client, if you don't like it you reject, otherwise you issue a JWT for them - which is never given to them.

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@evrys
Comment options

Answer selected by evrys
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants