← Back to plugin index

OAuth 2.0 Client Credentials Grant

Description

Configures an OAuth 2.0 Client Credentials Grant. Issued Access Token are self-contained JWTs. Therefore, tokens will not be persisted and cannot be revoked.

The Client Credentials Grant uses the following endpoint:

  1. /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/token - The Token Endpoint
Type name
OAuth2ClientCredentialsGrant
Class
com.airlock.iam.oauth2.application.configuration.OAuth2ClientCredentialsGrantConfig
May be used by
License-Tags
OAuthServer
Properties
Access Token Validity [s] (accessTokenValidity)
Description
Time in seconds for which an Access Token is valid.

Security Warning: a very long Access Token validity is not recommended. Clients can simply fetch a new access token by calling the endpoint again.

Attributes
Integer
Optional
Default value
180
Issuer (issuer)
Description
The issuer claim (iss) to include in the Access Token. If left empty the claim will not be included.
Attributes
String
Optional
Example
https://example.org/auth/rest/oauth2/authorization-servers/as-identifier
Example
custom-issuer
Audience (audience)
Description

The audience claim (aud) to include in the Access Token. If left empty the claim will not be included.

If there is one audience, the claim is written as a string, for multiple values as an array.

Attributes
String-List
Optional
Scope Policy (scopePolicy)
Description

The scope policy defines how the requested scopes are validated and processed (before the scope processors are applied).

Depending on the selected policy, the following rules apply:

  • Scopes Mandatory: It is mandatory for the client to request at least one scope, otherwise the request is denied.
    • For static clients for which 'Filter Requested Scopes' is enabled: the requested scopes are filtered against the client's allowed scopes and if the client has no allowed scopes, this is treated as if the client has not requested any scopes at all.
    • For static clients for which 'Filter Requested Scopes' is disabled: the requested scopes are not filtered (i.e. all scopes are allowed to be requested).
    • For persisted clients, the allowed scopes to request are stored per client and it can be configured there what the effect of an empty list of allowed scopes is.
  • Empty Scopes Allowed: It is optional for the client to request scopes.
    If scopes are requested:
    • For static clients for which 'Filter Requested Scopes' is enabled: the requested scopes are filtered against the client's allowed scopes and if the client has no allowed scopes, this is treated as if the client has not requested any scopes at all.
    • For static clients for which 'Filter Requested Scopes' is disabled: the requested scopes are not filtered (i.e. all scopes are allowed to be requested).
    • For persisted clients, the allowed scopes to request are stored per client and it can be configured there what the effect of an empty list of allowed scopes is.
  • Always Overwrite Scopes: The scopes requested by the client are ignored and replaced by the default scopes of the client. If the client has no default scopes, this is treated as if the client has not requested any scopes at all.
    With this policy, the 'Filter Requested Scopes' flag of static clients is ignored.
  • Empty Scopes Overwritten: When the client does not request any scopes, the request is treated as if the default scopes of this client were requested.
    If scopes are requested:
    • For static clients for which 'Filter Requested Scopes' is enabled: the requested scopes are filtered against the client's allowed scopes and if the client has no allowed scopes, this is treated as if the client has not requested any scopes at all.
    • For static clients for which 'Filter Requested Scopes' is disabled: the requested scopes are not filtered (i.e. all scopes are allowed to be requested).
    • For persisted clients, the allowed scopes to request are stored per client and it can be configured there what the effect of an empty list of allowed scopes is.
Attributes
Enum
Optional
Default value
EMPTY_SCOPES_ALLOWED
Granted Scope Processors (grantedScopeProcessors)
Description

Allows to further restrict the granted scopes (after applying the scope policy) before issuing the tokens.

The processors will be applied in the configured order and only scopes allowed by all processors may be granted.

If not configured, all granted scopes are assigned to the access token.

Notice: the scope processors are applied after the configured Scope Policy and thus have no influence on whether the requested scopes are allowed.

Attributes
Plugin-List
Optional
Assignable plugins
Signature (signature)
Description
The signature of the Access Token.
Attributes
Plugin-Link
Mandatory
Assignable plugins
YAML Template (with default values)

type: OAuth2ClientCredentialsGrant
id: OAuth2ClientCredentialsGrant-xxxxxx
displayName: 
comment: 
properties:
  accessTokenValidity: 180
  audience:
  grantedScopeProcessors:
  issuer:
  scopePolicy: EMPTY_SCOPES_ALLOWED
  signature: