Skip to content

Why can we set multiple redirect_uris ? #82

Description

@remdub

pas.plugins.oidc allows setting multiple redirect_uris.
According to OpenID Connect Core 1.0, only one redirect_uri should be sent in an authentication request.

Configuring multiple redirect_uris causes oic to raise an exception on login:

2025-09-11 13:31:42,177 DEBUG   [oic.oauth2:402][waitress-0] request: <class 'oic.oic.message.AuthorizationRequest'>
oic.oauth2.message.TooManyValues: redirect_uri

Question: Is supporting multiple redirect_uris intentional, or is this a bug/misconfiguration?

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingquestionFurther information is requested

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions