← Back to plugin index

OAuth 2.0 Header Client Secret (AS)

Description
Specifies the format of the client secret passed in the header of OAuth 2.0 requests.
Type name
OAuth2HeaderClientSecretMethod
Class
com.airlock.iam.oauth2.application.configuration.clientauthentication.OAuth2HeaderClientSecretMethodConfig
May be used by
License-Tags
OAuthServer
Properties
Header Field (headerField)
Description
Name of the header field containing the client secret.
Attributes
String
Optional
Default value
Authorization
Header Prefix (headerPrefix)
Description
Header field value prefix. The prefix must match exactly. May be empty.
A header prefix denotes the first part of a space delimited header value.
Eg. "Authorization: Basic 2q93nf8q23UIZFR2qfh98" where "Authorization" denotes the header field name, "Basic" the header prefix and "2q93nf8q23UIZFR2qfh98" the client secret value.
Attributes
String
Optional
Suggested values
Basic
Client Secret Format (clientSecretFormat)
Description
Client secret extraction pattern. If left blank, the client secret is the whole string. Otherwise this field must contain "$CLIENT_SECRET$" exactly once and may additionally contain "$CLIENT_ID$". When building requests the placeholders get replaced by their respective values, as specified in the OAuth 2.0 identity propagator plugin.
Attributes
String
Optional
Suggested values
$CLIENT_ID$:$CLIENT_SECRET$
Base64-Encoded Client Secret Value (base64EncodeClientSecretValue)
Description
Flag indicating whether the entire value (behind the optional prefix) is encoded in Base64; must be enabled for Basic-Auth.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: OAuth2HeaderClientSecretMethod
id: OAuth2HeaderClientSecretMethod-xxxxxx
displayName: 
comment: 
properties:
  base64EncodeClientSecretValue: false
  clientSecretFormat:
  headerField: Authorization
  headerPrefix: