Skip to content

add the /.well-known/oauth-authorization-server for the diccovery of the oauth endpoints. #64852

Description

@Mastersomy

Tip

Help move this idea forward

  • Use the 👍 reaction to show support for this feature.
  • Avoid commenting unless you have relevant information to add; unnecessary comments create noise for subscribers.
  • Subscribe to receive notifications about status changes and new comments.

Is your feature request related to a problem? Please describe.

it is not related to a Problem but supports two other enhancements nextcloud/context_agent#74 and nextcloud/context_agent#103

Describe the solution you'd like

I would like a file that is in the /.well-known/oauth-authorization-server location as described in the RFC8414 (https://datatracker.ietf.org/doc/html/rfc8414)
this file would look similar to the flowing:

{
  "issuer":"https://*********",
  "authorization_endpoint":"https://*********/index.php/apps/oauth2/authorize",
  "token_endpoint":"https://**********/index.php/apps/oauth2/api/v1/token",
  "response_types_supported":["code"],
  "grant_types_supported":["authorization_code","refresh_token"],
  "token_endpoint_auth_methods_supported":["client_secret_post","client_secret_basic"]
}

please check if the OAuth server can do all the things i described or if i missed some capability's.

once PKCE is implemented (#12881) this file should be changed to reflect this change.

Describe alternatives you've considered

the only Alternativ is to not implement it and document it so administrators can build it in there reverse proxys but i think this is only shading the responsibility onto the administrators without a real reason.

Additional context

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    0. Needs triagePending check for reproducibility or if it fits our roadmapenhancement

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions