← Back to plugin index

OAuth 2.0 Access Token Authenticator

Description

Authenticator that validates an OAuth 2.0 Access Token against the local persistence layer.

Note: When using certificate-bound access tokens with this Authenticator a "Certificate Token Credential Extractor" must be used as credential extractor to successfully authenticate the access token.

Type name
OAuth2AccessTokenAuthenticator
Class
com.airlock.iam.login.app.application.configuration.oauth.OAuth2AccessTokenAuthenticatorConfig
May be used by
License-Tags
OAuthServer
Properties
OAuth 2.0 Authorization Server Reference (authorizationServerReference)
Description
The unique identifier of the Authorization Server.
This must reference an Authorization Server in the top-level OAuth 2.0 Settings of the Loginapp.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Add Roles From Persistence (addRolesFromPersistence)
Description
Controls whether the user's roles from the persistency layer are added to the authenticated user.
Attributes
Boolean
Optional
Default value
true
Add Scopes As Roles (addScopesAsRoles)
Description
Controls whether the Access Token's scopes are added as roles to the authenticated user.
Attributes
Boolean
Optional
Default value
true
Add Context Data From Persistence (addContextDataFromPersistence)
Description
Controls whether the context data from the persistence layer is added to the authenticated user.
Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)

type: OAuth2AccessTokenAuthenticator
id: OAuth2AccessTokenAuthenticator-xxxxxx
displayName: 
comment: 
properties:
  addContextDataFromPersistence: true
  addRolesFromPersistence: true
  addScopesAsRoles: true
  authorizationServerReference: