Needed support for OIDC with generic Kubernetes clusters.
The OAuth 2.0 Password Grant Type has serious security ramifications and should not be used. According to the OAuth spec on security best practices (https://datatracker.ietf.org/doc/html/draft-ietf-oauth-security-topics#name-resource-owner-password-cre): "The resource owner password credentials grant [RFC6749] MUST NOT be used. This grant type insecurely exposes the credentials of the resource owner to the client."
Need to revamp the OIDC integration with kubernetes.
Created by Divij Kharche
·