Replies: 1 comment 3 replies
-
that's because of how Apache 2.4 works, it actually needs an extra |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
The sample auth_openidc.conf says:
But the source code has:
When testing with mod_auth_openidc 2.4.1 and Apache 2.4.41: I find that if a user authenticates but is not authorized, I get a 401 response. I have not set
AuthzSendForbiddenOnFailure
orOIDCUnAutzAction
Therefore, the documentation appears to be correct. However I don't understand why this is the case if
OIDC_DEFAULT_UNAUTZ_ACTION
isOIDC_UNAUTZ_RETURN403
? Is there something else which changes the default to RETURN401?Beta Was this translation helpful? Give feedback.
All reactions