Replies: 4 comments 3 replies
-
I'm not sure about the use case, in case of multiple IDPs the user is redirected to a discovery page that can optionally be skipped by configuring the 401 by default would only be returned for non-browser requests, you can change that by using |
Beta Was this translation helpful? Give feedback.
-
Sometimes the IdP is well identified by the server, but not by the client. In this case, it can use the Location header, like a browser. |
Beta Was this translation helpful? Give feedback.
-
Let me clarify: |
Beta Was this translation helpful? Give feedback.
-
That's usually right, unless the application opens a layer/frame/pop-up for the authentication |
Beta Was this translation helpful? Give feedback.
-
Hello.
Why not returning the Location header also with 401?
This would allow the client to know where to find the login page (although they need to know the syntax to login anyway). In some cases (when you have multiple IdP), it can be useful.
In the worst case, it won't hurt ...
Beta Was this translation helpful? Give feedback.
All reactions