This would require configuration with a whitelist of which OIDC IdPs to trust. Otherwise anybody could self-authorise a OIDC token (using their own IdP) and use that to log in.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies: