← Back to plugin index

OAuth 2.0 Remote Consent

Description

IAM will redirect the user to the configured remote consent URL to confirm OAuth 2.0 scopes.

The remote site must implement the Remote Consent Protocol. Please refer to the documentation for further information.

Type name
OAuth2RemoteConsent
Class
com.airlock.iam.oauth2.application.configuration.OAuth2RemoteConsentConfig
May be used by
License-Tags
RemoteConsent
Properties
Remote Consent URL (remoteConsentUrl)
Description
URL for the remote consent page to redirect the user to. For security reasons, only https URLs are allowed.
Attributes
String
Mandatory
Example
https://example.com/remoteconsent
Additional Claims (additionalClaims)
Description
Claims that are added to the consent request JWT in addition to the ones IAM always sends.
Attributes
Plugin-List
Optional
Assignable plugins
JWT Signer (signer)
Description
Settings that are used for signing the JWT contained in the consent request. This JWT is sent to the remote site.
Attributes
Plugin-Link
Mandatory
Assignable plugins
JWT Encrypter (encrypter)
Description
Settings that are used for encrypting the JWT contained in the consent request.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Validity [s] (validity)
Description
Number of seconds JWT contained in the consent request is valid for.
Attributes
Integer
Optional
Default value
1800
Callback URL (callbackUrl)
Description
URL for the callback from the remote consent page. This URL is included in the consent request JWT. The remote site must use this URL to redirect the user back to IAM. For security reasons, only https URLs are allowed.
Attributes
String
Mandatory
Example
https://iam.example.com/auth-login/ui/app/auth/oauth2/consent/confirm
Example
https://iam.example.com/auth-login/oauth2-confirm
JWT Signature Verifier (verifier)
Description
Settings that are used for verifying the MAC or signature of the JWT containing the user consent. This JWT is sent by the remote site.
Attributes
Plugin-Link
Mandatory
Assignable plugins
JWT Decrypter (decrypter)
Description
Settings that are used for decrypting the JWT sent by the remote site.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Airlock Gateway (WAF) Role for Remote Consent Site (airlockGatewayRole)
Description

The Airlock Gateway (WAF) role / credential that is set when accessing the remote consent site.

This can be used when IAM and the remote consent site provider are behind the same Airlock Gateway and you want to restrict the access to the remote consent site by a specific Gateway mapping.

The name of the credential can be followed by a colon and the idle timeout of the credential in seconds, e.g. "myrole:300" sets the credential "myrole" that will expire after 5 minutes of client inactivity.

With a second colon and a second number, the life-time can be set, e.g. "myrole:300:3600" will set the credential "myrole" for a maximum of 1 hour, but it will also expire after 5 minutes of client inactivity.

Attributes
String
Optional
Example
remote_consent_site
YAML Template (with default values)

type: OAuth2RemoteConsent
id: OAuth2RemoteConsent-xxxxxx
displayName: 
comment: 
properties:
  additionalClaims:
  airlockGatewayRole:
  callbackUrl:
  decrypter:
  encrypter:
  remoteConsentUrl:
  signer:
  validity: 1800
  verifier: