From 18031880330b563edb0c1fc4c0297d856028b233 Mon Sep 17 00:00:00 2001 From: dannyrb Date: Wed, 8 May 2019 13:06:15 -0400 Subject: [PATCH] Use a more secure flow, and be more explicit with redirects for security's sake --- public/config/example_openidc.js | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/public/config/example_openidc.js b/public/config/example_openidc.js index 0ff0c37a4..4f674ee48 100644 --- a/public/config/example_openidc.js +++ b/public/config/example_openidc.js @@ -15,6 +15,7 @@ window.config = { thumbnailRendering: 'wadors', // REQUIRED TAG: // https://github.com/OHIF/ohif-core/blob/59e1e04b92be24aee5d4402445cb3dcedb746995/src/studies/retrieveStudyMetadata.js#L54 + // TODO: Remove tag after https://github.com/OHIF/ohif-core/pull/19 is merged and we bump version requestOptions: { // auth: 'orthanc:orthanc', // undefined to use JWT + Bearer auth requestFromBrowser: true, @@ -31,8 +32,10 @@ window.config = { // Authorization Server URL authority: 'http://127.0.0.1/auth/realms/master', client_id: 'ohif-viewer', - redirect_uri: '/callback', // `OHIFStandaloneViewer.js` - response_type: 'id_token', + redirect_uri: 'http://127.0.0.1/callback', // `OHIFStandaloneViewer.js` + // "Authorization Code Flow" + // Resource: https://medium.com/@darutk/diagrams-of-all-the-openid-connect-flows-6968e3990660 + response_type: 'code', scope: 'openid', // email profile openid // ~ OPTIONAL post_logout_redirect_uri: '/logout-redirect.html',