From 99cd6068dc9a9ae23cce2b4265f939cbb8059c15 Mon Sep 17 00:00:00 2001 From: Amanda Anganes Date: Mon, 19 Aug 2013 16:55:56 -0400 Subject: [PATCH] Compare client_ids instead of Client objects --- .../main/java/org/mitre/oauth2/web/IntrospectionEndpoint.java | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openid-connect-server/src/main/java/org/mitre/oauth2/web/IntrospectionEndpoint.java b/openid-connect-server/src/main/java/org/mitre/oauth2/web/IntrospectionEndpoint.java index 8156dfddd..8b9755d17 100644 --- a/openid-connect-server/src/main/java/org/mitre/oauth2/web/IntrospectionEndpoint.java +++ b/openid-connect-server/src/main/java/org/mitre/oauth2/web/IntrospectionEndpoint.java @@ -115,7 +115,7 @@ public class IntrospectionEndpoint { if (authClient.isAllowIntrospection()) { // if it's the same client that the token was issued to, or it at least has all the scopes the token was issued with - if (authClient.equals(tokenClient) || authClient.getScope().containsAll(scopes)) { + if (authClient.getClientId().equals(tokenClient.getClientId()) || authClient.getScope().containsAll(scopes)) { // if it's a valid token, we'll print out information on it model.addAttribute("entity", token);