79371958

Date: 2025-01-20 16:14:31
Score: 0.5
Natty:
Report link

Some thoughts on this. First, you've to clarify the rights for the profile pictures. This heavily depends on the jurisdiction under which your services are measured. However, releasing pictures of humans, it's a promising idea to ask for consent by the humans themselves.

Secondly, there's no need for inclusion of the picture claim in the ID token. You could provide it solely on the user info endpoint as well, so only applications which make use of the claim will fetch this data from there.

In other words, it depends on your usecase and requirements.

Reasons:
  • Long answer (-0.5):
  • No code block (0.5):
  • Low reputation (0.5):
Posted by: KwaXi