← Back to plugin index

OAuth 2.0 Logging Settings

Description
Configures OAuth 2.0 logging behaviour for integration or error diagnostics.

Be aware that this settings are not meant for productive service unless it is required for error diagnostics.

Type name
OAuth2LoggingSettings
Class
com.airlock.iam.oauth2.application.configuration.logging.OAuth2LoggingSettings
May be used by
License-Tags
OAuthClient,OAuthServer
Properties
DEBUG Logs On INFO (logOnInfo)
Description
If enabled, all DEBUG logs are written to INFO instead.

Be aware that logging DEBUG information is detrimental to security because sensitive data might be logged. In addition, increased log output decreases the performance of the system

Attributes
Boolean
Optional
Default value
false
Token Logging Strategy (strategy)
Description
Configures how many characters of OAuth 2.0 Tokens are logged, e.g. during Token Introspection, Token Refresh or when receiving tokens as a client. If not configured, token content is always hidden in logs.

Security implications: Logging token information is detrimental to security. The logs will contain parts of OAuth 2.0 Tokens, which is generally not recommended. This increases the probability of guessing correct tokens for attackers with log access.
Especially in cases where tokens (e.g. Refresh Tokens) are long living, we advise against using this feature.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: OAuth2LoggingSettings
id: OAuth2LoggingSettings-xxxxxx
displayName: 
comment: 
properties:
  logOnInfo: false
  strategy: