From b410d28388563fd37f9c8dee3d220576a3457799 Mon Sep 17 00:00:00 2001 From: maliming Date: Fri, 21 Feb 2025 14:45:40 +0800 Subject: [PATCH] Disable `PushedAuthorizationBehavior` if app doesn't have permission. --- .../POST.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/docs/en/Community-Articles/2025-02-16-Using-Pushed-Authorization-Requests-In-ABP-Framework/POST.md b/docs/en/Community-Articles/2025-02-16-Using-Pushed-Authorization-Requests-In-ABP-Framework/POST.md index 281ed85d80..6f286e248a 100644 --- a/docs/en/Community-Articles/2025-02-16-Using-Pushed-Authorization-Requests-In-ABP-Framework/POST.md +++ b/docs/en/Community-Articles/2025-02-16-Using-Pushed-Authorization-Requests-In-ABP-Framework/POST.md @@ -153,6 +153,17 @@ AddAbpOpenIdConnect("oidc", options => }); ``` +The `UseIfAvailable` value is the default behavior, and ABP has enabled the `PAR` endpoint globally. Make sure all your web applications have been granted the `OpenIddictConstants.Permissions.Endpoints.PushedAuthorization` permission to use the PAR endpoint. If not, you should disable the `PushedAuthorizationBehavior` in the `OpenIdConnectOptions`. + +```csharp +AddAbpOpenIdConnect("oidc", options => +{ + //... + options.PushedAuthorizationBehavior = PushedAuthorizationBehavior.Disable; + //... +}); +``` + > Not all authentication clients support PAR. For example, Blazor WASM does not yet support it. ## Summary