← Back to plugin index

OAuth 2.0 Flow Client

Description
OAuth 2.0 Flow Client Settings. The settings define the OAuth 2.0 handshake and can be referenced in flows through the provider ID. When the OAuth 2.0 authorization was successful, the OAuth 2.0 Access Token is stored in the user session and can be used by the plugin OAuth 2.0 Tokens Map in the ID Propagation to provide the Access Token to for the backends.
Type name
OAuth2SsoFlowClientSettings
Class
com.airlock.iam.oauth2.application.configuration.OAuth2SsoFlowClientSettings
May be used by
License-Tags
OAuthClient
Properties
HTTP Client (httpClient)
Description
HTTP client used for token endpoint requests.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Token/PAR Endpoint Authentication (tokenEndpointAuthentication)
Description
Specifies how the client secret is included in requests to the token and pushed authorization request (PAR) endpoints.

RFC 6749 suggests to use the HTTP Basic authentication scheme ('OAuth 2.0 Basic Auth Client Secret').

Attributes
Plugin-Link
Optional
Assignable plugins
Authorization Endpoint URL (authorizationEndpointURL)
Description
Authorization endpoint URL to obtain Authorization Codes from.
Attributes
String
Mandatory
Example
https://airlock.iam/auth/ui/app/auth/oauth2/authorization-servers/asId/authorize
Example
https://airlock.iam/auth/oauth2/v3/asId/authorize
Example
https://accounts.google.com/o/oauth2/auth
Example
https://login.live.com/oauth20_authorize.srf
Pushed Authorization Request Endpoint URL (pushedAuthorizationRequestEndpointURL)
Description
The pushed authorization request endpoint URI to send the Authorization Request to. If this property is set, the OAuth2 client will send all Authorization Requests according to the PAR specification as defined in RFC 9126.
Attributes
String
Optional
Example
https://airlock.iam/auth/rest/oauth2/authorization-servers/asId/par
Example
https://as.example.org/as/par
Token Endpoint URL (tokenEndpointURL)
Description
Token endpoint URL to get Access and Refresh Tokens.
Attributes
String
Mandatory
Example
https://airlock.com/auth/rest/oauth2/authorization-servers/asId/token
Example
https://accounts.google.com/o/oauth2/token
Example
https://login.live.com/oauth20_token.srf
Scopes To Request (scopesToRequest)
Description
Scopes to request from the authorization endpoint. Note that some authorization servers deny requests with no requested scopes.

Scopes may only contain the following characters: 0-9, A-Z, a-z, !, #, $, %, &, ', (, ), *, +, ',', -, ., /, :, ;, <, >, =, ?, @, [, ], ^, _, `, {, }, |, ~

Attributes
String-List
Optional
PKCE Challenge Method (pkceChallengeMethod)
Description
Configures the PKCE challenge method.
Attributes
Enum
Optional
Default value
S256
Provider Identifier (providerId)
Description
An identifier to identify the OAuth 2.0 Authorization Server or OpenID Provider.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Client Redirect URI (clientRedirectURI)
Description

Defines the redirect URI (redirect_uri) parameter value to be included in OAuth 2.0 requests. The authorization response will then be sent to this URI by the authorization server (AS) or OpenID Provider (OP).

For redirects to the default IAM Loginapp UI use the "OAuth 2.0 Default UI Client Redirect URI".

Attributes
Plugin-Link
Mandatory
Assignable plugins
Resource Requests (resourceRequests)
Description

Resource requests that will be executed to determine the identity of the user on the provider.

An OAuth 2.0 credential containing data of these resources is instantiated. This credential can then be used by plugins such as OAuth 2.0 Credential Roles Provider and OAuth 2.0 Credential Context Data Map to provide the data from the Authorization Server to the ID Propagation. This enables the ability to propagate the data to the backends.
Attributes
Plugin-List
Optional
Assignable plugins
Account Linking Self-Service (accountLinkingSelfService)
Description

If enabled, this provider is available in the account linking self-service.

Users can link their IAM account with this provider to have an alternative authentication method.

The account link management is available for authenticated users under the Loginapp URL: <loginapp-uri>/ui/app/protected/account-links

Attributes
Plugin-Link
Optional
License-Tags
OAuthAccountLinking,OAuthSocialRegistration
Assignable plugins
Missing Account Link Red Flag (missingAccountLinkRedFlag)
Description

If configured, the flow will raise the configured red flag and continue in case no user could be identified using an account link.

This red flag can then be used by a following subflow to:
  1. be triggered (by using Account Linking Required Red Flag Condition as condition for the subflow)
  2. identify the local user with authentication steps
  3. link the identified user to the provider account and take down the red flag (by using Missing Account Link Step as step in the subflow)
Attributes
Plugin-Link
Optional
License-Tags
OAuthAccountLinking,OAuthSocialRegistration
Assignable plugins
Client ID (clientId)
Description
Client ID identifying Airlock IAM at the authorization / token and resource endpoint of the OAuth 2.0 provider.
Only alphanumeric characters and '-_.' are allowed.
Attributes
String
Mandatory
Validation RegEx: [a-zA-Z0-9-_.]+
Example
example-app
Example
crypticyButUniqueAppId01953utjhu91823rih
Client Secret (clientSecret)
Description
Client secret used to verify the client.
Attributes
String
Mandatory
Sensitive
Access Token Request Method (accessTokenRequestMethod)
Description
HTTP method to use for Access Token requests.
Attributes
Plugin-Link
Optional
Assignable plugins
Logging Settings (loggingSettings)
Description
Custom OAuth 2.0 client logging behaviour for integration or error diagnostics.
Attributes
Plugin-Link
Optional
Assignable plugins
Enable Account Linking (enableAccountLinking)
Description
If enabled, this provider will solely function as an alternative authentication method for the accounts of the Loginapp's user store. Meaning that users having an IAM account and an account link to a provider account can authenticate using this provider. Account links can be created by
  • Users using the self-service
  • The automated registration
  • Auto-link feature
Attributes
Boolean
Optional
License-Tags
OAuthAccountLinking,OAuthSocialRegistration
Default value
false
Auto-link IAM Account Based on Context Data Field (autoLinkExistingUsersContextDataField)
Description
If the provider's account has the same unique value for the given context data field as an existing account of the Loginapp's user persister, it will be linked with the provider's account. If left empty none of the existing accounts will be linked.

To be able to match the context data value, it is required to add an 'OAuth 2.0 Remote Context Data Resource' with a 'Local Context Data Key' equal to this value to the resource mappings and have a context data column entry equal to this value in the Loginapp's user persister.

If this feature is used in combination with 'Automated Account Registration', no accounts will be registered that have been auto-linked.

Security Warning: For security reasons this should always be a context data field that is globally unique (e.g. email or phone number) and was previously verified by the IAM registration process (channel verification) and the provider's registration process. If this is not guaranteed, an attacker may be able to use this feature to log into a victim's IAM account.

Attributes
String
Optional
License-Tags
OAuthAccountLinking,OAuthSocialRegistration
Suggested values
email, mtan_number
Automated Account Registration (accountRegistrationConfig)
Description
Enables automated IAM account registration with data from this provider.

The user must always confirm the account registration.

If this feature is used in combination with 'Auto-link IAM Account Based on Context Data Field', no accounts will be registered that have been auto-linked.

Security Warning: For automated account registration, the provider's data is used without additional validation. In particular:

  • Identity verification for mTAN numbers and/or email addresses is currently not supported.
  • Data validation (e.g. using regular expressions) is currently not supported.
  • The provider's data that is used to create the account is not displayed to the user and the user is not asked to confirm the data, e.g. using transaction approval.
Therefore, if this feature is used, the provider must guarantee that the provided data is valid (e.g. identity-verified and validated). IAM must trust the provider to do appropriate validation.

Attributes
Plugin-Link
Optional
License-Tags
OAuthSocialRegistration
Assignable plugins
YAML Template (with default values)

type: OAuth2SsoFlowClientSettings
id: OAuth2SsoFlowClientSettings-xxxxxx
displayName: 
comment: 
properties:
  accessTokenRequestMethod:
  accountLinkingSelfService:
  accountRegistrationConfig:
  authorizationEndpointURL:
  autoLinkExistingUsersContextDataField:
  clientId:
  clientRedirectURI:
  clientSecret:
  enableAccountLinking: false
  httpClient:
  loggingSettings:
  missingAccountLinkRedFlag:
  pkceChallengeMethod: S256
  providerId:
  pushedAuthorizationRequestEndpointURL:
  resourceRequests:
  scopesToRequest:
  tokenEndpointAuthentication:
  tokenEndpointURL: