Post #2630831
2026-05-12 17:20 UTC
@heiglandreas@phpc.social
The mental model for OIDC is:
"Who authenticated the user?"
You still must answer:
"Why do I trust this OP for this organization/domain?"
This is an application trust/onboarding problem, not an authentication protocol problem.
Replies (0)
No replies.