← Back to plugin index

OAuth 2.0/OIDC Authorization Server

Description
OAuth 2.0 / OpenID Connect Authorization Server settings for all AS-centric endpoints under the paths /<loginapp-uri>/oauth2/v3/ and /<loginapp-uri>/rest/oauth2/.
Type name
OAuth2AS
Class
com.airlock.iam.login.app.misc.configuration.oauth.as.OAuth2ASConfig
May be used by
License-Tags
OAuthServer
Properties
Identifier (identifier)
Description
The unique identifier of this AS. This identifier is used in the endpoint URLs.
Attributes
Plugin-Link
Optional
Assignable plugins
Application UI (applicationUi)
Description

Defines which application UI will handle the authorization requests or redirect to a custom application UI.

This allows clients to use the URL (/<loginapp-uri>/oauth2/v3/<as-identifier>/authorize) from the OAuth 2.0 metadata to redirect to a custom application UI.

Attributes
Plugin-Link
Optional
Assignable plugins
Issuer ID (issuerId)
Description

The issuer ID of this AS.

This is used both for the metadata endpoint and the OIDC authorization code flow, therefore it must be configured when using either one.

It must end with a slash followed by the unique identifier of the AS.

Note that the issuer ID usually represents the front-facing URL of this authentication server and may be used by clients to derive the URL of the OpenID Connect Discovery or the OAuth 2.0 Metadata endpoint. See plugin documentation of those endpoints for more details about the logic and rules of this derivation.

Attributes
Plugin-Link
Optional
Assignable plugins
OAuth 2.0 Grants/OIDC Flows (oauth2Grants)
Description
The supported OAuth 2.0 / OpenID Connect grants and related endpoints of this AS.
Attributes
Plugin-Link
Optional
Assignable plugins
Static Clients (staticClients)
Description

The statically configured clients of this AS.

In contrast to the "Persisted Clients", these clients are only contained in the configuration and are not stored on the database. This is useful when the entire set of clients is known upfront at configuration time.

Static clients can be combined with persisted clients. If both sources contain a client with the same name, the static client will take precedence without raising an error.

Attributes
Plugin-Link
Optional
Assignable plugins
Persisted Clients (persistedClients)
Description

The persisted clients on the database of this AS.

This plugin is required when Dynamic Client Registration is used. Persisted clients are stored on the database and currently can only be inserted using Dynamic Client Registration.

Persisted clients can be combined with static clients. If both sources contain a client with the same name, the static client will take precedence without raising an error.

Attributes
Plugin-Link
Optional
Assignable plugins
Metadata Endpoint (metadataEndpoint)
Description

Endpoint for OAuth 2.0 Authorization Server Metadata (RFC 8414).

The Endpoint is located at /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/.well-known/oauth-authorization-server and must be mapped by a WAF or proxy to the external URL <issuer id>/.well-known/oauth-authorization-server

Attributes
Plugin-Link
Optional
Assignable plugins
Token Endpoint (tokenEndpoint)
Description

Configuration of the token endpoint.

This endpoint is called by the clients in order to exchange an authorization code or to refresh a Refresh Token.

The token endpoint is located at /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/token

Attributes
Plugin-Link
Optional
Assignable plugins
Token Introspection Endpoint (tokenIntrospectionEndpoint)
Description

Endpoint for OAuth 2.0 Token Introspection (RFC 7662) located at /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/introspect

Attributes
Plugin-Link
Optional
Assignable plugins
Token Revocation Endpoint (tokenRevocationEndpoint)
Description

Endpoint for OAuth 2.0 Token Revocation (RFC 7009) located at /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/revoke

Attributes
Plugin-Link
Optional
Assignable plugins
Dynamic Client Registration (dynamicClientRegistration)
Description

The OAuth 2.0 Dynamic Client Registration endpoint settings.

The registration endpoint must be configured in the Loginapp's settings for "Technical Client Registration", where a flow containing an "OAuth 2.0 Client Registration Step" can be configured.

Attributes
Plugin-Link
Optional
License-Tags
TechClientRegistration
Assignable plugins
Resource Endpoint (resourceEndpoint)
Description

Configuration of all resource endpoints located at /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/resources/<resource-name>

For all resource endpoints, a valid access token must be provided.

Attributes
Plugin-Link
Optional
Assignable plugins
Session Management Endpoint (sessionManagementEndpoint)
Description

Endpoint for the custom OAuth 2.0 Session Management.

If not configured, the session management endpoint is disabled for this AS.

The session management endpoint is located under /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/sessions/

Attributes
Plugin-Link
Optional
Assignable plugins
Discovery Endpoint (discoveryEndpoint)
Description

Enables the OpenID Connect Discovery Endpoint.

The endpoint is available under /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/.well-known/openid-configuration

This endpoint can only be configured when an OpenID Connect flow has been configured.

Attributes
Plugin-Link
Optional
Assignable plugins
UserInfo Endpoint (userInfoEndpoint)
Description

Enables the UserInfo Endpoint according to the OpenID Connect Specification.

The endpoint is available under /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/userinfo

This endpoint can only be configured when an OpenID Connect flow has been configured.

Attributes
Plugin-Link
Optional
Assignable plugins
Session Management 1.0 (openIdConnectSessionManagement)
Description

Enables OpenID Connect Session Management 1.0 according to the OpenID Connect Session Management Specification.

It allows a website relying on the user's authentication to monitor his login status at the OpenID Provider on an ongoing basis so that the Relying Party can log out an End-User who has logged out of the OpenID Provider.

Enabling this will allows the client to embed the OP-Iframe using the url /<loginapp-uri>/oauth2/v3/<as-identifier>/check-session

Attributes
Plugin-Link
Optional
Assignable plugins
User Data Source (userStore)
Description
Data source to read and update user related data during OAuth 2.0 requests.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Token Data Provider (tokenDataProvider)
Description
Token Data Provider responsible for persisting OAuth 2.0 Tokens.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Session Repository (sessionRepository)
Description
OAuth 2.0 session repository config.
Attributes
Plugin-Link
Optional
Assignable plugins
Consent Storage Repository (consentStorageRepository)
Description

If configured, enables storing user given consent in a database.

During an OAuth 2.0 flow, IAM can remember the scopes for which a user has given his consent and therefore skips the consent screen if all requested scopes were granted/denied in a previous flow.

This setting is required when a Local Consent is used with enabled Consent Storage.

Attributes
Plugin-Link
Optional
Assignable plugins
Username Transformation (usernameTransformation)
Description

Allows to convey a different username than the IAM user ID.

This transformed username is used in the following locations:

  • OpenID Connect ID Token: sub claim
  • OpenID Connect ID Token: Custom username claim
  • Access Token as JWT: sub claim
  • UserInfo Endpoint: sub claim
  • Token Introspection Endpoint: sub claim
  • Username Resource

The transformers are asked to provide an alternative name in the configured order. Every transformer may interrupt the transformation chain and provide a final result or pass it on to the next transformer to potentially apply further transformations.

If left blank, the username of the authenticated user is used for all endpoints mentioned above.

Note that this setting can be overridden for each "OAuth 2.0 Static Client".

Attributes
Plugin-List
Optional
Assignable plugins
Role Transformation (roleTransformationConfigs)
Description

A list of role transformation rules used to modify the collection of roles to propagate.

The role transformation rules are executed at the following locations in-order from top to bottom:

  • OpenID Connect ID Token
  • Access Token as JWT
  • UserInfo Endpoint
  • User Roles Resource
Attributes
Plugin-List
Optional
Assignable plugins
Token Generator Settings (tokenGeneratorConfig)
Description
All tokens, e.g. Access Tokens, will be generated using these settings.
Attributes
Plugin-Link
Optional
Assignable plugins
Logging Settings (loggingSettings)
Description
Custom OAuth 2.0 server logging behaviour for integration or error diagnostics.
Attributes
Plugin-Link
Optional
Assignable plugins
Delete Tokens on Logout (deleteTokensOnLogout)
Description

Configures which OAuth 2.0 / OpenID Connect tokens and sessions of the user are deleted when the user logs out:

  • None: No tokens are deleted. Note that OpenID Connect Back-Channel Logout 1.0 is not supported in this case even if there are clients that specify a "Back-Channel Logout URI".
  • Session: All tokens from the current user's session are deleted.
  • All: All tokens of this user are deleted.

Note: If "Session" or "All" is selected, OpenID Connect Back-Channel Logout 1.0 is only performed for (client) sessions which are based on the current user's session.

Security Warning: Affects only actively triggered logouts, but not session timeouts. Therefore, the validity of each OAuth 2.0 token type should be configured and checked appropriately.

Attributes
Enum
Optional
Default value
SESSION
Delete Tokens On Password Change (deleteTokensOnPasswordChange)
Description
Indicates whether all persisted tokens and sessions of the user are deleted when the user changes a password.
Attributes
Boolean
Optional
Default value
false
Delete Tokens On User Locked (deleteTokensOnUserLocked)
Description
Indicates whether all persisted tokens and sessions of the user are deleted when the user is locked.

Note: This setting only applies to users locked in the Loginapp. To delete tokens for users locked by admins, configure the corresponding settings within the Adminapp.

Attributes
Boolean
Optional
Default value
false
Persist Claims (persistClaims)
Description
When enabled, custom claims in Access- and ID Tokens are generated and persisted on successful flow completion. On token generation, the claim values are loaded from the database. This allows deterministic claim values in tokens, i.e. claim values do not change when tokens are refreshed.

When not enabled, claim values are newly evaluated every time a new token is created. This may lead to different claim values every time a token is requested. This was the default behaviour in all IAM <= version 8.2 releases.

However, regardless of this setting, the following claims are always freshly evaluated every time a token is requested:

  • iat - Issue Time
  • nbf - Not Valid Before
  • exp - Expiration Time (claim is not included if token has infinite validity)
  • jti - JWT ID (random value)
  • random - A random value for the token entropy
  • scope - A JSON array defining the scope of the access token
  • cnf - The token binding (if applicable)

Note: The column 'claims' in the database table 'oauth2_session' is required to use this feature. A runtime error occurs if this feature is active and the database was not migrated.

Attributes
Boolean
Optional
Default value
true
Cache-Control Response Header (cacheControlResponseHeader)
Description
If left empty the 'Cache-Control' response header is set to 'no-store, no-cache, must-revalidate'. If configured, the 'Cache-Control' response header is set to the specified value for the following endpoints:
  • /auth-login/rest/oauth2/authorization-servers/authorizationServerId/jwks/
  • /auth-login/rest/oauth2/authorization-servers/authorizationServerId/.well-known/openid-configuration/
  • /auth-login/rest/oauth2/authorization-servers/authorizationServerId/.well-known/oauth-authorization-server/
Attributes
String
Optional
Example
public, max-age=3600
YAML Template (with default values)

type: OAuth2AS
id: OAuth2AS-xxxxxx
displayName: 
comment: 
properties:
  applicationUi:
  cacheControlResponseHeader:
  consentStorageRepository:
  deleteTokensOnLogout: SESSION
  deleteTokensOnPasswordChange: false
  deleteTokensOnUserLocked: false
  discoveryEndpoint:
  dynamicClientRegistration:
  identifier:
  issuerId:
  loggingSettings:
  metadataEndpoint:
  oauth2Grants:
  openIdConnectSessionManagement:
  persistClaims: true
  persistedClients:
  resourceEndpoint:
  roleTransformationConfigs:
  sessionManagementEndpoint:
  sessionRepository:
  staticClients:
  tokenDataProvider:
  tokenEndpoint:
  tokenGeneratorConfig:
  tokenIntrospectionEndpoint:
  tokenRevocationEndpoint:
  userInfoEndpoint:
  userStore:
  usernameTransformation: