OAuth 2.0 Flow Client
httpClient) tokenEndpointAuthentication) RFC 6749 suggests to use the HTTP Basic authentication scheme ('OAuth 2.0 Basic Auth Client Secret').
authorizationEndpointURL) pushedAuthorizationRequestEndpointURL) tokenEndpointURL) scopesToRequest) Scopes may only contain the following characters: 0-9, A-Z, a-z, !, #, $, %, &, ', (, ), *, +, ',', -, ., /, :, ;, <, >, =, ?, @, [, ], ^, _, `, {, }, |, ~
pkceChallengeMethod) providerId) clientRedirectURI) Defines the redirect URI (redirect_uri) parameter value to be included in OAuth 2.0 requests. The authorization response will then be sent to this URI by the authorization server (AS) or OpenID Provider (OP).
For redirects to the default IAM Loginapp UI use the "OAuth 2.0 Default UI Client Redirect URI".
resourceRequests) Resource requests that will be executed to determine the identity of the user on the provider.
An OAuth 2.0 credential containing data of these resources is instantiated. This credential can then be used by plugins such as OAuth 2.0 Credential Roles Provider and OAuth 2.0 Credential Context Data Map to provide the data from the Authorization Server to the ID Propagation. This enables the ability to propagate the data to the backends.accountLinkingSelfService) If enabled, this provider is available in the account linking self-service.
Users can link their IAM account with this provider to have an alternative authentication method.The account link management is available for authenticated users under the Loginapp URL: <loginapp-uri>/ui/app/protected/account-links
missingAccountLinkRedFlag) If configured, the flow will raise the configured red flag and continue in case no user could be identified using an account link.
This red flag can then be used by a following subflow to:- be triggered (by using Account Linking Required Red Flag Condition as condition for the subflow)
- identify the local user with authentication steps
- link the identified user to the provider account and take down the red flag (by using Missing Account Link Step as step in the subflow)
clientId) Only alphanumeric characters and '-_.' are allowed.
clientSecret) accessTokenRequestMethod) loggingSettings) enableAccountLinking) - Users using the self-service
- The automated registration
- Auto-link feature
autoLinkExistingUsersContextDataField) To be able to match the context data value, it is required to add an 'OAuth 2.0 Remote Context Data Resource' with a 'Local Context Data Key' equal to this value to the resource mappings and have a context data column entry equal to this value in the Loginapp's user persister.
If this feature is used in combination with 'Automated Account Registration', no accounts will be registered that have been auto-linked.
Security Warning: For security reasons this should always be a context data field that is globally unique (e.g. email or phone number) and was previously verified by the IAM registration process (channel verification) and the provider's registration process. If this is not guaranteed, an attacker may be able to use this feature to log into a victim's IAM account.
accountRegistrationConfig) The user must always confirm the account registration.
If this feature is used in combination with 'Auto-link IAM Account Based on Context Data Field', no accounts will be registered that have been auto-linked.
Security Warning: For automated account registration, the provider's data is used without additional validation. In particular:
- Identity verification for mTAN numbers and/or email addresses is currently not supported.
- Data validation (e.g. using regular expressions) is currently not supported.
- The provider's data that is used to create the account is not displayed to the user and the user is not asked to confirm the data, e.g. using transaction approval.
type: OAuth2SsoFlowClientSettings
id: OAuth2SsoFlowClientSettings-xxxxxx
displayName:
comment:
properties:
accessTokenRequestMethod:
accountLinkingSelfService:
accountRegistrationConfig:
authorizationEndpointURL:
autoLinkExistingUsersContextDataField:
clientId:
clientRedirectURI:
clientSecret:
enableAccountLinking: false
httpClient:
loggingSettings:
missingAccountLinkRedFlag:
pkceChallengeMethod: S256
providerId:
pushedAuthorizationRequestEndpointURL:
resourceRequests:
scopesToRequest:
tokenEndpointAuthentication:
tokenEndpointURL: