Microsoft Entra ID cannot issue an access token for multiple audiences. The new --entra-id-redeem-scope option (alpha config: microsoftEntraIDConfig.redeemScope) allows requesting a broad scope list at authorization time while sending a narrowed, single-audience scope when exchanging the authorization code for tokens, as permitted by RFC 6749 section 3.3. If unset, behaviour is unchanged. Applies to both the client-secret and federated-token redemption paths of the entra-id provider. Fixes #2751 Signed-off-by: Mathias Mikkel Neerup <mane@tv2.dk> |
||
|---|---|---|
| .. | ||
| apis | ||
| app | ||
| authentication | ||
| cookies | ||
| encryption | ||
| header | ||
| ip | ||
| logger | ||
| middleware | ||
| providers | ||
| proxyhttp | ||
| requests | ||
| sessions | ||
| upstream | ||
| util | ||
| validation | ||
| version | ||
| watcher | ||