reject vs ignore on plain (or outside PAR) authorization request parameters

Issue #347 duplicate
Filip Skokan created an issue
  1. shall reject authorization requests sent without [@I-D.lodderstedt-oauth-par] or authorization request parameters sent outside of the PAR request, except for request_uri and client_id

Is ignoring parameters outside of PAR as defined by JAR/PAR not sufficient? This is introducing yet another splinter of already so fractured specification family.

Comments (6)

  1. Torsten Lodderstedt

    Wouldn’t be require_pushed_authorization_requests set to true define the desired behavior?

  2. Log in to comment