Skip to content
Discussion options

You must be logged in to vote

PR 345 introduced regenerating client assertions to enable retrying DPoP nonce requests. In your use case, you need to take ownership of generating the PAR request yourself because of the requirement of sending multiple resource URIs. So I don't think you're doing anything wrong here.

I would agree that the best approach is to not call the inner handler from Duende.AccessTokenManagement.OpenIdConnect. Since you're also setting the client assertion retrieved from the IClientAssertionService, you're basically doing the same thing as the inner handler (and more).

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@iseneirik
Comment options

Answer selected by iseneirik
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants