You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Mar 20, 2019. It is now read-only.
The client credentials grant type MUST only be used by confidential clients.
DotNetOpenAuth does not check for that internally. I can get access token for public clients successfully.
However, since it can be verified inside method CheckAuthorizeClientCredentialsGrant(IAccessTokenRequest accessRequest) easily, I'm not sure if this should be considered as a bug or not.
As per RFC 6749,
The client credentials grant type MUST only be used by confidential clients.
DotNetOpenAuth does not check for that internally. I can get access token for public clients successfully.
However, since it can be verified inside method CheckAuthorizeClientCredentialsGrant(IAccessTokenRequest accessRequest) easily, I'm not sure if this should be considered as a bug or not.