it's this more section 4-3 http://tools.ietf.org/html/rfc6749#section-4.3 It's where you have a trust reletionship with the app. As pre-requesites the app store user/password. It matches keycloak "Direct Grant" option. We should provide an implementation and test it with our oauth2 providers:Keycloak, Google and Facebook.
For client crededntials grant we need another ticket, but i think KC does not cover it.
|