← Back to plugin index

OAuth 2.0/OIDC Clients

Description
Configuration for OAuth 2.0 / OpenID Connect SSO (Airlock IAM as Client).
Type name
OAuth2SSOClientSettings
Class
com.airlock.iam.login.app.misc.configuration.OAuth2SSOClientSettings
May be used by
License-Tags
OAuthClient
Properties
AS Setting For Flow Clients (flowClientSettings)
Description
The settings for the OAuth 2.0 / OpenID Connect providers for flow based authorizations.
Attributes
Plugin-List
Mandatory
Assignable plugins
Legacy Client Endpoint Support (legacyClientEndpointSupport)
Description

OAuth 2.0 legacy client endpoint (/oauth2-client) compatibility support.

This property must be configured when flow-based OAuth 2.0/OpenID Connect is used, and the client endpoint (redirect_uri) URI cannot be changed on the Authorization Server to the new endpoint URI:

/<loginapp-uri>/ui/app/oauth2/client

When this property is set, the browser accessing the legacy client endpoint URI will be redirected to the configured target, if and only if all of the following conditions apply:

  • The request contains an authorization response
  • "AS Setting For Flow Clients" has at least one entry configured

All OAuth 2.0 URL parameters will be retained in the redirect.

Attributes
Plugin-Link
Optional
Assignable plugins
Account Link Persister (accountLinkPersister)
Description
Persists links from IAM accounts to provider accounts.

The database entry contains

  • The IAM user name
  • The configured 'Provider Identifier' of the 'OAuth 2.0 Flow Client' or 'OIDC Flow Client'
  • The provider's username defined by the 'OAuth 2.0 Remote Username Resource' resource mapping
  • Optionally the additional information to help the user identify the provider's account defined by 'Account Info Resource Key' of the 'Account Linking Self-Service'

If a user chooses to login in with a provider that has 'Account Linking Self-Service' enabled and a link matching the 'Provider Identifier' and the provider's username is found, the IAM user of the entry will be authenticated.

If users are allowed to change their usernames, a 'Account Link Consistency User Change Listener' in the Loginapp's user persister should be configured.

Attributes
Plugin-Link
Optional
License-Tags
OAuthAccountLinking,OAuthSocialRegistration
Assignable plugins
YAML Template (with default values)

type: OAuth2SSOClientSettings
id: OAuth2SSOClientSettings-xxxxxx
displayName: 
comment: 
properties:
  accountLinkPersister:
  flowClientSettings:
  legacyClientEndpointSupport: