oauth - Identity Server3 Client Claims vs Scope Claims -
is possible insert dynamically client claims, similar scope claims overriding methods such getprofiledataasync or getclaimsfromaccount?
note: if insert client claims directly configuration of client, claims inserted in access token, need somehow way insert claims dynamically somewhere. flag alwayssendclientclaims set true.
the scenario following: have multiple clients, 2 resources (web api & signalr) , in order access resource need user details such userid, companyid, etc., same resources. 1 idea, tried , working, create scope , add scope claims every needed user detail , use userservice inject necessary claims. if have different scopes accessing resources? don't want have scope claim duplicated in different claims, want specify common user details @ client claims included in access token, , leave specifics scope claims.
i appreciate suggestion in direction.
Comments
Post a Comment