Will we see other OAuth providers follow suit and start randomizing email addresses and user IDs returned to apps? I hope so! Ironically, Facebook first started doing this a few years ago when they launched app-scoped user IDs.
3
1
1
3
That is all. Thanks for listening.
2
10
Now I would just love to have a quick guide for using Apple Sign In as an Okta generic oidc inbound provider. Is this possible already ?
1
I actually just got this working last night!
2
1
Do you know where you can find the .well-known/openid-configuration on the apple url? Do they even use it?
1
I haven't found it yet. I wouldn't be surprised if they just don't have that endpoint
2
1
So talked with the Apple engineers here at WWDC: They don't have that endpoint, they also will not expose user_info or a revocation endpoint. The user_info will only be sent once and only once then you will only get a unique id again. Only scopes available now are name and email
3
Just verified again, and I don't get back name or email address when I request "name email" scope. I did find a bug where apparently Apple is ignoring the "scope" parameter after the very first time you authorize an app though, so could be related.
1
That is not a bug that is feature. They told me they will only give you the info once. Probably why scope won’t matter after your first invoke.
2
I will go test this out with new app credentials though to confirm. Thanks for the lead!

Jun 6, 2019 · 10:28 PM UTC

1