> In my experience with OAuth, one of the principle issues is that it's less a protocol and more a skeleton of a protocol.
Because it is, really.
OAuth (2.0) is really the backbone for OpenID.
Because it is, really.
OAuth (2.0) is really the backbone for OpenID.
I’m using the same keycloak setup for almost 2 years now, with upgrades
There is a flag to restore the old behavior but it doesn't work in newer version. Strangely, an older instance of keycloak I run still uses the old behavior even after being upgraded to latest version, so this issue seems to only affect new instance only.