← Back to plugin index

JWT Ticket Decoder

Description

Configures the JWT (JSON Web Token) ticket decoder.

The decoder verifies a ticket's MAC or signature and decrypts it in case encryption is enabled. A ticket is required to contain at least a subject ('sub' claim) and an expiration date ('exp' claim). Additionally an issuer ('iss' claim) and audience ('aud' claim) might be required, if configured. A 'not before' ('nbf' claim) is validated if present but only mandatory if configured to be.

If the ticket starts with a "Bearer " prefix (e.g. from a HTTP Authorization header), the prefix is removed before decoding the JWT.

Type name
JwtTicketDecoderSettings
Class
com.airlock.iam.common.application.configuration.jwt.JwtTicketDecoderSettings
May be used by
Properties
Username Ticket Key (usernameTicketKey)
Description

The ticket key for the username. The username in the 'sub' claim of the JWT will be written to the IAM ticket using this ticket key.

If using this ticket decoder for the loginapp's "SSO Ticket Feature", the value of this attribute must be "username".

Attributes
String
Mandatory
Example
username
Not Before Is Mandatory (notBeforeIsMandatory)
Description
If set to true, the incoming JWT must have a 'nbf' claim. Note that this setting does not affect validation of the 'nbf' claim. If this claim is present, it will always be validated.
Attributes
Boolean
Optional
Default value
true
Valid Not Before Skew (validNotBeforeSkew)
Description
The configured value in seconds is added to the current time before validating the 'nbf' claim. The motivation to compare the 'nbf' claim with a time in the future is to avoid clock synchronization problems with the JWT issuer.
Attributes
Integer
Optional
Default value
5
Not Before Ticket Key (notBeforeTicketKey)
Description
The ticket key for the not before claim. The JWT not before claim ('nbf') will be written to that field. Note that this field is optional. If not set, the 'nbf' claim of the JWT won't be written into the ticket.
Attributes
String
Optional
Issued At Is Mandatory (issuedAtIsMandatory)
Description
If set to true, the incoming JWT must have a 'iat' claim.
Attributes
Boolean
Optional
Default value
true
Issued At Ticket Key (issuedAtTicketKey)
Description
The ticket key for the issued at claim. The JWT issued at claim ('iat') will be written to that field. Note that this field is optional. If not set, the 'iat' claim of the JWT won't be written into the ticket.
Attributes
String
Optional
Issuer Is Mandatory (issuerIsMandatory)
Description
If set to true, the incoming JWT must have an 'iss' claim. Note that this setting does not affect validation of the 'iss' claim. If this claim is present, it will always be validated against the configured list of allowed issuers.
Attributes
Boolean
Optional
Default value
true
Allowed Issuers (allowedIssuers)
Description
The allowed values for the issuer claim ('iss') in the JWT. If not configured, the issuer claim is not validated.
Attributes
String-List
Optional
Issuer Ticket Key (issuerTicketKey)
Description
The ticket key for the issuer claim. The JWT issuer claim ('iss') will be written to that field. Note that this field is optional. If not set, the 'iss' claim of the JWT won't be written into the ticket.
Attributes
String
Optional
Audience Is Mandatory (audienceIsMandatory)
Description
If set to true, the incoming JWT must have a 'aud' claim. Note that this setting does not affect validation of the 'aud' claim. If this claim is present, it will always be validated against the configured expected audience entry.
Attributes
Boolean
Optional
Default value
false
Allowed Audiences (allowedAudiences)
Description
A list of accepted entries for the audience claim ('aud') of the JWT. If not configured, the audience claim is not validated. To pass validation there must be at least one entry that is present in the audience claim and in the configured list.
Attributes
String-List
Optional
Audience Ticket Key (audienceTicketKey)
Description
The ticket key for the audience claim. The JWT audience claim ('aud') will be written to that field. Note that this field is optional. If not set, the 'aud' claim of the JWT won't be written into the ticket.
Attributes
String
Optional
Jwt Id Is Mandatory (jwtIdIsMandatory)
Description
If set to true, the incoming JWT must have a 'jti' claim.
Attributes
Boolean
Optional
Default value
false
Claims Stored As JSON (claimsStoredAsJson)
Description
The claim names that should be interpreted as JSON in the received JWT. If such a claim does not exist in the JWT, it is not written into the ticket. The ticket key is always the claim name. If the JSON of this claim is invalid, an exception is thrown.
Note: It is not allowed to specify registered claims here. Registered claims are always propagated as specified in RFC 7519.
Attributes
String-List
Optional
Jwt Id Ticket Key (jwtIdTicketKey)
Description
The ticket key for the JWT ID claim. The JWT ID claim ('jti') will be written to that field. Note that this field is optional. If not set, the 'jti' claim of the JWT won't be written into the ticket. In order to use the 'jti' claim as unique ID for the ticket, you must specify 'uniqueId' here. This is mandatory for Ticket-SSO-Setups.
Attributes
String
Optional
Example
uniqueId
Additional Claim Validators (additionalClaimValidators)
Description
List of additional claim validators.
Attributes
Plugin-List
Optional
Assignable plugins
Signature Verifier (signatureVerifier)
Description
The settings that are used for verifying the MAC or signature of the JWT.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Decrypter (decrypter)
Description
The settings that are used for decrypting the JWT. If no plugin is configured, the JWT must be unencrypted.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: JwtTicketDecoderSettings
id: JwtTicketDecoderSettings-xxxxxx
displayName: 
comment: 
properties:
  additionalClaimValidators:
  allowedAudiences:
  allowedIssuers:
  audienceIsMandatory: false
  audienceTicketKey:
  claimsStoredAsJson:
  decrypter:
  issuedAtIsMandatory: true
  issuedAtTicketKey:
  issuerIsMandatory: true
  issuerTicketKey:
  jwtIdIsMandatory: false
  jwtIdTicketKey:
  notBeforeIsMandatory: true
  notBeforeTicketKey:
  signatureVerifier:
  usernameTicketKey:
  validNotBeforeSkew: 5