0

With federated security (e.g. OIDC + external identity provider) the owner of the REST API has no control over the user profile, so the owner of the API cannot store any application-specific information (such as user role or claim) in the user profile. That means that on each request the REST API has to retrieve the application-specific user profile with the application-specific user role. Am I missing something?

isobretatel
  • 3,812
  • 7
  • 34
  • 49

0 Answers0