Hi Anji,
Of course it is possible to configure an OIDC federation to a third party application which is behind a WebSEAL junction on the same domain. The fact that the Relying Party is behind a junction doesn't change anything for the configuration of OIDC.
I also don't find that configuration so unusual. It is true that federation protocols such as OIDC and SAML are designed to be able to federate completely independent systems. But that does not preclude them from being used in environments where both systems are under your control.
In fact we use it widely in our environment. Not yet for OIDC, but we have integrated several third party applications with SAML, and also protected these applications with WebSEAL. Of course we could also have federated the application in the traditional way and let the user directly access the back-end system, but as a security team we don't have too much trust in third party applications. We want to make sure that only authenticated and authorized users can access the system.
------------------------------
Laurent LA Asselborn
------------------------------