Skip to content

Clarification on sub claim #2571

Answered by nabokihms
MidasLamb asked this question in Q&A
Discussion options

You must be logged in to vote

Hello, @MidasLamb. As you've mentioned, a sub claim in Dex token consists of two things: one is a unique id provided by an external oidc provider, and the second is a unique id from the Dex config, which identifies an external provider. Frauds still need access to reconfigure a Dex instance to impersonate a user from another oidc provider.

Note: sub claim returned by Dex is not a plain text string encoded in base64, yet a protobuf serialized string with two fields.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by MidasLamb
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants