HTTP Header Token Extractor (as SSO Credential)
Extracts a token from an HTTP header, decodes it using the specified ticket decoder (e.g. JWT) and provides a "Single-Sign-On-Credential" to the authenticator.
This extractor can be used to verify JWTs in "Authorization" headers (to remove the "Bearer "-Prefix from the header value use "Header Value Conversion Pattern" and "Header Value Conversion Replacement").
This extractor can only be used with authenticators that are able to process Single-Sign-On-Credentials (e.g. the "SSO Credential Authenticator").
headerName) urlEncodingScheme) decoder) usernameKey) rolesKey) contextProperties) headerValueConversionPattern) Regular expression pattern containing a group (a section in parentheses) that can be used in conjunction with property "Header Value Conversion Replacement" in order to transform the header value before it is decoded. If the header value does not match the pattern at all, no transformation is performed.
Example: The pattern "^Bearer (.*)$" and the replacement pattern "$1" will transform the header value "Bearer ABCD1234" to "ABCD1234" before it is decoded.
headerValueConversionReplacement)
type: HttpHeaderTokenExtractor
id: HttpHeaderTokenExtractor-xxxxxx
displayName:
comment:
properties:
contextProperties:
decoder:
headerName:
headerValueConversionPattern:
headerValueConversionReplacement:
rolesKey: roles
urlEncodingScheme: UTF-8
usernameKey: username