Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix OpenIdApplicationStep to remove permissions for flows that are no longer enabled #11720

Closed
kevinchalet opened this issue May 17, 2022 · 1 comment · Fixed by #11721
Closed

Comments

@kevinchalet
Copy link
Member

#10136 updated OpenIdApplicationStep to support updates but unfortunately, permissions removal was not implemented: if you remove an allowed flow from an already configured recipe, the permissions corresponding to that flow (grant type permissions, endpoint permissions and response types permissions) must be removed too (otherwise, the flow is still considered allowed).

Basically, the same logic present in ApplicationController.Edit() should be used in the recipe step.

@kevinchalet
Copy link
Member Author

/cc @deanmarcussen

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants