OAuth 2.0 Pushed Authorization Requests
Description
Configures OAuth 2.0 Pushed Authorization Requests (PAR).
The endpoint is located at /<loginapp-uri>/rest/oauth2/authorization-servers/<as-identifier>/par. Clients must authenticate to call this endpoint. The PAR endpoint uses the same authentication method as configured for the token endpoint.
To prevent attacks like swapping an obtained request_uri, clients should make use of PKCE, use a unique state parameter, or use the OIDC "nonce" parameter.
Properties
Request URI Lifetime [s] (
requestUriLifetime) Description
The lifetime of the generated PAR request URI in seconds.
A general guidance for the validity time would be less than a minute.
Attributes
Integer
Optional
Default value
30
OAuth 2.0 PAR Repository (
repository) Description
OAuth 2.0 PAR repository configuration to store pushed authorization requests in the database.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Require PAR (
requirePar) Description
If this flag is set, all authorization requests made to the authorization server must use PAR. Non-PAR requests will lead to an invalid_request error.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)
type: OAuth2Par
id: OAuth2Par-xxxxxx
displayName:
comment:
properties:
repository:
requestUriLifetime: 30
requirePar: false