Client Registration Clarification
The registration of clients from the application configuration was removed in 614822a1 in favor of dynamic client registration. The corresponding configuration configuration property was removed in fd5abc4f but the documentation was not updated (here). To keep existing deployments and tests working, a database migration was introduced, that basically hardcodes a bunch of clients (here).
I think this is less than ideal:
- At the very least, the documentation should be updated to reflect these changes. Ideally, there should be some explanation on how DCR works.
- The hardcoded clients should be removed for production deployments. Otherwise every deployment will have the same clients and secrets by default.
Personally, I think that the registration of clients via the application configuration should remain an option. Maybe AAS could check the configuration options during startup and add entries to the database?
Edited by Cristina Pauna