diff --git a/docs/en/Community-Articles/2025-02-16-Using-Pushed-Authorization-Requests-In-ABP-Framework/POST.md b/docs/en/Community-Articles/2025-02-16-Using-Pushed-Authorization-Requests-In-ABP-Framework/POST.md index 281ed85d80..6f286e248a 100644 --- a/docs/en/Community-Articles/2025-02-16-Using-Pushed-Authorization-Requests-In-ABP-Framework/POST.md +++ b/docs/en/Community-Articles/2025-02-16-Using-Pushed-Authorization-Requests-In-ABP-Framework/POST.md @@ -153,6 +153,17 @@ AddAbpOpenIdConnect("oidc", options => }); ``` +The `UseIfAvailable` value is the default behavior, and ABP has enabled the `PAR` endpoint globally. Make sure all your web applications have been granted the `OpenIddictConstants.Permissions.Endpoints.PushedAuthorization` permission to use the PAR endpoint. If not, you should disable the `PushedAuthorizationBehavior` in the `OpenIdConnectOptions`. + +```csharp +AddAbpOpenIdConnect("oidc", options => +{ + //... + options.PushedAuthorizationBehavior = PushedAuthorizationBehavior.Disable; + //... +}); +``` + > Not all authentication clients support PAR. For example, Blazor WASM does not yet support it. ## Summary