OIDC Flow Client
httpClient) tokenEndpointAuthentication) RFC 6749 suggests to use the HTTP Basic authentication scheme ('OAuth 2.0 Basic Auth Client Secret').
tokenEndpointURL) authorizationEndpointURL) pushedAuthorizationRequestEndpointURL) pkceChallengeMethod) signatureValidator) endSessionEndpoint) Note that the AS must support this feature.
scopesToRequest) Scopes may only contain the following characters: 0-9, A-Z, a-z, !, #, $, %, &, ', (, ), *, +, ',', -, ., /, :, ;, <, >, =, ?, @, [, ], ^, _, `, {, }, |, ~
claimsToRequest) If the client wants to validate claims (e.g. returned in the ID Token), "Additional Claim Validators" can be configured. Note that the acr claim is validated separately. Refer to the property description of "Validate ACR Claim".
acrValuesClaim) If the client wants to enforce a certain acr (e.g. to enforce strong authentication), "Additional Claim Validators" can be configured to validate if the requested acr is contained in the ID Token. Otherwise the authorization fails.
includeNonce) includeLanguageParameter) maxAuthenticationAge) prompt) Available options:
Note: If the setting does not match the authorization server policy the authorization process may fail. For example, if user interaction is suppressed but login is required.
customAuthorizationRequestParameters) login_hint or display as well as non-standard parameters.
Note: If a parameter is set both using the standard functionality and custom authorization request parameter, the standard parameter will take precedence.
customIssuerClaim) If not set, the issuer URI in the ID Token is only compared to the host name of the authorization endpoint.
audienceClaimValidationMethod) Options:
- STANDARD: Standard audience claim validation as defined in the OpenID Connect Core specification.
- REDIRECT_URL: Compatibility option. The audience claim must be a valid URL and the host must match the host of the redirect URL used by Airlock IAM.
- CUSTOM: Compatibility option. The audience claim must exactly match a custom value supplied by 'Custom Audience Claim'.
customAudienceClaim) enableAcrValidation) Validation fails if no acr claim is present or the contained value does not match one of the requested acr values.
Validation succeeds if no acr values are requested or the value of the acr claim in the ID Token matches one of the requested acr values.
Disable to not validate the acr claim. In addition, it is possible to define custom acr validation using "Additional Claim Validators".
additionalClaimValidators) If any of the validators fail, the ID Token is rejected and authorization fails.
idTokenResources) An OAuth 2.0 credential containing data of these resources is instantiated. This credential can then be used by plugins such as OAuth 2.0 Credential Roles Provider and OAuth 2.0 Credential Context Data Map to provide the data from the Authorization Server to the ID Propagation. This enables the ability to propagate the data to the backends.
postLogoutRedirectUrl) It is recommended to define this property to ensure a seamless application flow. If not configured, the AS defines how to respond to the logout request.
providerId) clientRedirectURI) Defines the redirect URI (redirect_uri) parameter value to be included in OAuth 2.0 requests. The authorization response will then be sent to this URI by the authorization server (AS) or OpenID Provider (OP).
For redirects to the default IAM Loginapp UI use the "OAuth 2.0 Default UI Client Redirect URI".
resourceRequests) Resource requests that will be executed to determine the identity of the user on the provider.
An OAuth 2.0 credential containing data of these resources is instantiated. This credential can then be used by plugins such as OAuth 2.0 Credential Roles Provider and OAuth 2.0 Credential Context Data Map to provide the data from the Authorization Server to the ID Propagation. This enables the ability to propagate the data to the backends.accountLinkingSelfService) If enabled, this provider is available in the account linking self-service.
Users can link their IAM account with this provider to have an alternative authentication method.The account link management is available for authenticated users under the Loginapp URL: <loginapp-uri>/ui/app/protected/account-links
missingAccountLinkRedFlag) If configured, the flow will raise the configured red flag and continue in case no user could be identified using an account link.
This red flag can then be used by a following subflow to:- be triggered (by using Account Linking Required Red Flag Condition as condition for the subflow)
- identify the local user with authentication steps
- link the identified user to the provider account and take down the red flag (by using Missing Account Link Step as step in the subflow)
clientId) Only alphanumeric characters and '-_.' are allowed.
clientSecret) accessTokenRequestMethod) loggingSettings) enableAccountLinking) - Users using the self-service
- The automated registration
- Auto-link feature
autoLinkExistingUsersContextDataField) To be able to match the context data value, it is required to add an 'OAuth 2.0 Remote Context Data Resource' with a 'Local Context Data Key' equal to this value to the resource mappings and have a context data column entry equal to this value in the Loginapp's user persister.
If this feature is used in combination with 'Automated Account Registration', no accounts will be registered that have been auto-linked.
Security Warning: For security reasons this should always be a context data field that is globally unique (e.g. email or phone number) and was previously verified by the IAM registration process (channel verification) and the provider's registration process. If this is not guaranteed, an attacker may be able to use this feature to log into a victim's IAM account.
accountRegistrationConfig) The user must always confirm the account registration.
If this feature is used in combination with 'Auto-link IAM Account Based on Context Data Field', no accounts will be registered that have been auto-linked.
Security Warning: For automated account registration, the provider's data is used without additional validation. In particular:
- Identity verification for mTAN numbers and/or email addresses is currently not supported.
- Data validation (e.g. using regular expressions) is currently not supported.
- The provider's data that is used to create the account is not displayed to the user and the user is not asked to confirm the data, e.g. using transaction approval.
type: OpenIDConnectSsoFlowClientSettings
id: OpenIDConnectSsoFlowClientSettings-xxxxxx
displayName:
comment:
properties:
accessTokenRequestMethod:
accountLinkingSelfService:
accountRegistrationConfig:
acrValuesClaim:
additionalClaimValidators:
audienceClaimValidationMethod: STANDARD
authorizationEndpointURL:
autoLinkExistingUsersContextDataField:
claimsToRequest:
clientId:
clientRedirectURI:
clientSecret:
customAudienceClaim:
customAuthorizationRequestParameters:
customIssuerClaim:
enableAccountLinking: false
enableAcrValidation: true
endSessionEndpoint:
httpClient:
idTokenResources:
includeLanguageParameter: false
includeNonce: true
loggingSettings:
maxAuthenticationAge: 0
missingAccountLinkRedFlag:
pkceChallengeMethod: S256
postLogoutRedirectUrl:
prompt:
providerId:
pushedAuthorizationRequestEndpointURL:
resourceRequests:
scopesToRequest:
signatureValidator:
tokenEndpointAuthentication:
tokenEndpointURL: