Per 4.3 (Token Issuance - issuer checks) what if there are some failures?
-
Multiple 1P cookies? And user is required to select between multiple accounts currently logged in at the Issuer side (for example, multiple @gmail.com accounts on a home PC).
-
You note "cookies sent represent a logged in user, and if the logged in user " ...
- What if the user's login is expired using the email address, but the Issuer wants to make sure a valid login is done before returning "email_verified": true? (also, desiring 2FA usage at the Issuer side.)
Is there any browser flow to redirect to an Issuer page to have the Issuer confirm login details before returning to the original page flow?
Per 4.3 (Token Issuance - issuer checks) what if there are some failures?
Multiple 1P cookies? And user is required to select between multiple accounts currently logged in at the Issuer side (for example, multiple @gmail.com accounts on a home PC).
You note "cookies sent represent a logged in user, and if the logged in user " ...
Is there any browser flow to redirect to an Issuer page to have the Issuer confirm login details before returning to the original page flow?