← Back to plugin index

OAuth 2.0 Response Modes

Description

Restricts the accepted response mode(s) per OpenId Connect Flow.

By default only the standard response mode for each flow is allowed ('query' for Authorization Code Grant, 'fragment' for Hybrid Flow).

If the standard response mode of a particular flow is unselected, requests without a response_mode parameter will be rejected.

Type name
OAuth2ResponseMode
Class
com.airlock.iam.login.app.misc.configuration.oauth.as.oauth2.OAuth2ResponseModeConfig
May be used by
License-Tags
OAuthServer
Properties
Allow "query" (authorizationCodeFlowQueryResponseMode)
Description

Enables the query response mode for Authorization Code Flow. This is the default mode according to the specification if a client does not request a particular response mode.

If unselected, requests without a response_mode parameter will be rejected.

Attributes
Boolean
Optional
Default value
true
Allow "fragment" (authorizationCodeFlowFragmentResponseMode)
Description

Enables the fragment response mode for Authorization Code Flow.

If not enabled, requests that explicitly request this mode will be rejected.

Attributes
Boolean
Optional
Default value
false
Allow "form_post" (authorizationCodeFlowFormPostResponseMode)
Description

Enables the form_post response mode for Authorization Code Flow.

If not enabled, requests that explicitly request this mode will be rejected.

Attributes
Boolean
Optional
Default value
false
Allow "query" (hybridFlowQueryResponseMode)
Description

Enables the query response mode for Hybrid Flow.

If not enabled, requests that explicitly request this mode will be rejected.

Attributes
Boolean
Optional
Default value
false
Allow "fragment" (hybridFlowFragmentResponseMode)
Description

Enables the fragment response mode for Hybrid Flow. This is the default mode according to the specification if a client does not request a particular response mode.

If unselected, requests without a response_mode parameter will be rejected.

Attributes
Boolean
Optional
Default value
true
Allow "form_post" (hybridFlowFormPostResponseMode)
Description

Enables the form_post response mode for Hybrid Flow.

If not enabled, requests that explicitly request this mode will be rejected.

Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: OAuth2ResponseMode
id: OAuth2ResponseMode-xxxxxx
displayName: 
comment: 
properties:
  authorizationCodeFlowFormPostResponseMode: false
  authorizationCodeFlowFragmentResponseMode: false
  authorizationCodeFlowQueryResponseMode: true
  hybridFlowFormPostResponseMode: false
  hybridFlowFragmentResponseMode: true
  hybridFlowQueryResponseMode: false