A Symfony relying party¶
The client of reference for this provider is Symfony's own oidc_login authenticator. Anything Beffroi
emits must be consumable by it with no patch, and anything it can verify, Beffroi must produce. When a
limit shows up in the authenticator, it is fixed upstream in Symfony rather than worked around here.
That makes a Symfony application the shortest path to a sign-in you can watch end to end: a firewall with
oidc_login pointed at the issuer, a client declared on the provider side, and the callback the
authenticator expects.
This page will carry that configuration, both halves of it: the firewall that signs a person in, and the
access_token firewall of a resource server checking what the provider issued, by introspection or by
verifying an at+jwt itself.
Until it is written, the reference relying party is
beffroi-php/oidc-demo: a Symfony application on oidc_login, a
resource server that checks the same access token several ways, and a ladder of demonstration clients from
the simplest to one that pushes a signed request, reads a signed response, holds a bound token and opens an
encrypted ID token.