From a8a7acce1e8b17521a1ef6dae93e7e8e7881d7f6 Mon Sep 17 00:00:00 2001 From: Richard van der Hoff Date: Tue, 9 Mar 2021 18:10:17 +0000 Subject: [PATCH] update UIA --- proposals/2858-Multiple-SSO-Identity-Providers.md | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/proposals/2858-Multiple-SSO-Identity-Providers.md b/proposals/2858-Multiple-SSO-Identity-Providers.md index 825771fe..1e49d070 100644 --- a/proposals/2858-Multiple-SSO-Identity-Providers.md +++ b/proposals/2858-Multiple-SSO-Identity-Providers.md @@ -131,10 +131,11 @@ client could be a matter for a future improvement, but is out of scope for now.) ### Notes on user-interactive auth -For the case of User Interactive Auth the server would just give the standard -SSO flow option without any `identity_providers` as there is no method for -a client to choose an IdP within that flow at this time nor is it as -essential. +No change is proposed to the SSO flow for User-Interactive Authentication. + +For a reauthentication operation, the server implementation is free to choose +any suitable IdP to authenticate the user. (Often, this will simply be +the IdP that the user logged in with.) ### Proposed initial identifiers for the `brand` indentifier