iam icon indicating copy to clipboard operation
iam copied to clipboard

Check authZ to scim/Me endpoint

Open federicaagostini opened this issue 10 months ago • 0 comments

Right now, if one wants to retrieve the scim/Me resource with a token, it has to contain the scim:read scope, otherwise an "Insufficient scope for this resource" exception is thrown. From web interface, a session is enough to query the endpoint.

The issue is arised by the necessity to expone CERN username coming from CERN SSO oidc login (present in the scim endpoint).

We can either revisit access to the scim/Me resource just based on the token containing a subject which identifies a user, or adding this information to another endpoint (account?).

federicaagostini avatar Apr 16 '24 17:04 federicaagostini