HF RL Explorer

OAuth2/OIDC Authentication Compliance Issues and UserInfo Caching

OAuth2/OIDC Authentication Compliance Issues and UserInfo Caching: a task in LegoFlow-SWE (Harbor dataset). According to the OIDC specification, the aud (audience) claim is mandatory only in ID tokens, not in UserInfo responses. The current implementation incorrectly rejects authentication when…

The task

According to the OIDC specification, the `aud` (audience) claim is mandatory **only** in ID tokens, **not** in UserInfo responses. The current implementation incorrectly rejects authentication when the Identity Provider (IdP) returns a UserInfo response that does not contain the `aud` claim. This breaks valid OAuth2…

Part of Lego-X/LegoFlow-SWE.