Browse Source

Disable `PushedAuthorizationBehavior` if app doesn't have permission.

pull/22165/head
maliming 2 years ago
parent
commit
b410d28388
No known key found for this signature in database GPG Key ID: A646B9CB645ECEA4
  1. 11
      docs/en/Community-Articles/2025-02-16-Using-Pushed-Authorization-Requests-In-ABP-Framework/POST.md

11
docs/en/Community-Articles/2025-02-16-Using-Pushed-Authorization-Requests-In-ABP-Framework/POST.md

@ -153,6 +153,17 @@ AddAbpOpenIdConnect("oidc", options =>
});
```
The `UseIfAvailable` value is the default behavior, and ABP has enabled the `PAR` endpoint globally. Make sure all your web applications have been granted the `OpenIddictConstants.Permissions.Endpoints.PushedAuthorization` permission to use the PAR endpoint. If not, you should disable the `PushedAuthorizationBehavior` in the `OpenIdConnectOptions`.
```csharp
AddAbpOpenIdConnect("oidc", options =>
{
//...
options.PushedAuthorizationBehavior = PushedAuthorizationBehavior.Disable;
//...
});
```
> Not all authentication clients support PAR. For example, Blazor WASM does not yet support it.
## Summary

Loading…
Cancel
Save