From 95ad492100794b98714a30120b0049594352919d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?K=C3=A9vin=20Chalet?= Date: Fri, 10 Sep 2021 15:57:44 +0200 Subject: [PATCH] Update OpenIddictServerBuilder.AllowImplicitFlow()/AllowPasswordFlow() to indicate that the implicit and password flows are not recommended for new applications --- src/OpenIddict.Server/OpenIddictServerBuilder.cs | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/src/OpenIddict.Server/OpenIddictServerBuilder.cs b/src/OpenIddict.Server/OpenIddictServerBuilder.cs index d136ccb3..c181ff62 100644 --- a/src/OpenIddict.Server/OpenIddictServerBuilder.cs +++ b/src/OpenIddict.Server/OpenIddictServerBuilder.cs @@ -1017,6 +1017,7 @@ namespace Microsoft.Extensions.DependencyInjection /// /// The grant type associated with the flow. /// The . + [EditorBrowsable(EditorBrowsableState.Advanced)] public OpenIddictServerBuilder AllowCustomFlow(string type) { if (string.IsNullOrEmpty(type)) @@ -1063,6 +1064,10 @@ namespace Microsoft.Extensions.DependencyInjection /// https://tools.ietf.org/html/rfc6749#section-4.2 and /// http://openid.net/specs/openid-connect-core-1_0.html#ImplicitFlowAuth. /// + /// + /// The implicit flow is not recommended for new applications and should + /// only be enabled when maintaining backward compatibility is important. + /// /// The . public OpenIddictServerBuilder AllowImplicitFlow() => Configure(options => @@ -1089,6 +1094,10 @@ namespace Microsoft.Extensions.DependencyInjection /// Enables password flow support. For more information about this specific /// OAuth 2.0 flow, visit https://tools.ietf.org/html/rfc6749#section-4.3. /// + /// + /// The password flow is not recommended for new applications and should + /// only be enabled when maintaining backward compatibility is important. + /// /// The . public OpenIddictServerBuilder AllowPasswordFlow() => Configure(options => options.GrantTypes.Add(GrantTypes.Password));