← Back to plugin index

OAuth 2.0 Metadata Endpoint

Description

Configuration of an endpoint for OAuth 2.0 Authorization Server Metadata. (RFC 8414).

Note that this endpoint also works for authentication servers in OpenID Connect mode.

As dictated by RFC 8414, the front-facing URL of this endpoint must be derived from the configured issuer ID. For instance, if the issuer ID is "https://example.com/auth/rest/oauth2/authorization-servers/main-as", the front-facing URL of this endpoint must be "https://example.com/.well-known/oauth-authorization-server/auth/rest/oauth2/authorization-servers/main-as".

Note that the well-known URI string ".well-known/oauth-authorization-server/" is not appended but inserted after the host part of the issuer ID to be compliant. Regardless of this fact, IAM serves this endpoint at a URL where the well-known URI string is appended to the base URL of the AS (e.g., "https://example.com/auth/rest/oauth2/authorization-servers/main-as/.well-known/oauth-authorization-server"). In order to fully meet the specification, an Airlock Gateway (WAF) mapping should be used to map the compliant URL to the one used by IAM.

Type name
OAuth2MetadataEndpoint
Class
com.airlock.iam.login.app.misc.configuration.oauth.as.OAuth2MetadataEndpointConfig
May be used by
License-Tags
OAuthServer
Properties
Issuer Validation Mode (issuerValidationMode)
Description

Defines how IAM should behave when a mismatch is detected at runtime between the configured issuer ID and the front-facing URL of the request to this endpoint.

Available options:

  • Ignore: Ignore a mismatch and respond with metadata
  • Log Only: Log a warning and respond with metadata when there is a mismatch
  • Fail: Respond with a server error when there is a mismatch

Attributes
Enum
Optional
Default value
FAIL
YAML Template (with default values)

type: OAuth2MetadataEndpoint
id: OAuth2MetadataEndpoint-xxxxxx
displayName: 
comment: 
properties:
  issuerValidationMode: FAIL