Standard 4.3.4.1

Issue #168 resolved
John Bradley created an issue

If the response_type parameter in the Authorization Request includes the string value "token" or "id_token", all response parameters SHOULD be added to the fragment component of the redirection URI. Otherwise, the response parameters are added to the query component of the redirection URI.

Change SHOULD to MUST, this is not optional for interoperability.

Comments (4)

  1. Log in to comment