← Back to plugin index

OIDC Session Management

Description
OpenID Connect Session Management settings according to the OpenID Connect Session Management Specification
Type name
OpenIDConnectSessionManagement
Class
com.airlock.iam.oauth2.application.configuration.OpenIDConnectSessionManagementConfig
May be used by
License-Tags
OAuthServer
Properties
Same Site Policy (sameSitePolicy)
Description

Specifies the 'SameSite' cookie attribute of the OP User Agent State cookie.

The correct choice of this property is essential for the correct operation of this feature:

  • For same-domain scenarios, 'Lax' should be chosen. In this case, the cookie will only be accessible when the top-level page (which includes the OP iframe) is in the same domain as the OP iframe)
  • For cross-domain scenarios, 'None' must be chosen. In this case, 'Secure' is also automatically appended because modern browsers only accept those cookies on a secure connection
  • To rely on browser default behavior (not recommended), 'No SameSite Attribute' can be chosen, resulting in cookies usually interpreted as 'Lax' depending on the browser version.

Attributes
Enum
Optional
Default value
LAX
Debug (debug)
Description
When enabled, the OP Iframe writes debug logs to the browser console on every message, allowing to debug the functionality and find the reason for a possible 'error' response. In addition, the origin check endpoint logs a debug log when an origin is not accepted with further information.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: OpenIDConnectSessionManagement
id: OpenIDConnectSessionManagement-xxxxxx
displayName: 
comment: 
properties:
  debug: false
  sameSitePolicy: LAX