Honoring semantics for forceAuthn flag in the same manner as SAML

Description

Then adding the forceAuthn="true" flag within the OIDC.SSO bean this does not cause the authorization flow to trigger authentication in presence of an existing session.

The flag seems to be ignored altogether

Environment

None

Activity

Henri Mikkonen April 11, 2022 at 3:24 PM

Added configurable forceAuthnPredicate for the InitializeAuthenticationContext action. It’s set to ForceAuthnProfileConfigPredicate (protocol-independent) by default.

Fixed

Details

Assignee

Reporter

Components

Fix versions

Affects versions

Created April 7, 2022 at 10:28 AM
Updated April 15, 2022 at 5:32 PM
Resolved April 11, 2022 at 3:24 PM