Skip to content

Conversation

@glpatcern
Copy link
Member

Following the implementation of the code flow in Nextcloud as part of cs3org/OCM-STA#6, we discussed to recommend in the spec that the token exchange flow MAY be performed even in the absence of a requirement, in case the remote endpoint offers the token-exchange capability.

This PR specifies this, implying that in such a case a fall-back must be implemented to normal bearer-token (or basic auth) access, should the token exchange fail.

cc @enriquepablo @mickenordin

@glpatcern glpatcern requested a review from mickenordin January 12, 2026 17:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants