Is API management not validating token Audience something Wanted ? #4684
Unanswered
scandinave
asked this question in
Q&A
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi,
I've seen that management API does not validate the token audience. The AudienceRule is not applied in the
DelegatedAuthenticationExtension
. I think it must be done like it is in theOauth2ServiceExtension
otherwise the Management API will authorize tokens emitted by the correct Authorization Server but intended for a different resources serveur protected with the authorization serverDo I miss something?
Beta Was this translation helpful? Give feedback.
All reactions