Will we see other OAuth providers follow suit and start randomizing email addresses and user IDs returned to apps? I hope so!
Ironically, Facebook first started doing this a few years ago when they launched app-scoped user IDs.
3
1
1
3
Anyway, if you're curious about what this will look like, I wrote a sample app that uses Sign In with Apple so you can see how it works.
developer.okta.com/blog/2019…
3
3
2
25
Now I would just love to have a quick guide for using Apple Sign In as an Okta generic oidc inbound provider. Is this possible already ?
1
Do you know where you can find the .well-known/openid-configuration on the apple url?
Do they even use it?
1
So talked with the Apple engineers here at WWDC:
They don't have that endpoint, they also will not expose user_info or a revocation endpoint. The user_info will only be sent once and only once then you will only get a unique id again. Only scopes available now are name and email
3
Just verified again, and I don't get back name or email address when I request "name email" scope.
I did find a bug where apparently Apple is ignoring the "scope" parameter after the very first time you authorize an app though, so could be related.
1
I will go test this out with new app credentials though to confirm. Thanks for the lead!
Jun 6, 2019 · 10:28 PM UTC
1


