diff --git a/openid-connect-client/src/main/java/org/mitre/openid/connect/client/OIDCSignedRequestFilter.java b/openid-connect-client/src/main/java/org/mitre/openid/connect/client/OIDCSignedRequestFilter.java index 16d8598b1..5cbc2ed67 100644 --- a/openid-connect-client/src/main/java/org/mitre/openid/connect/client/OIDCSignedRequestFilter.java +++ b/openid-connect-client/src/main/java/org/mitre/openid/connect/client/OIDCSignedRequestFilter.java @@ -118,7 +118,7 @@ public class OIDCSignedRequestFilter extends AbstractOIDCAuthenticationFilter { response.addCookie(nonceCookie); - claims.setClaim("nonce", nonceCookie); + claims.setClaim("nonce", nonce); try { signingAndValidationService.signJwt(jwt);