OAuth 2.0 SSO Ticket Resource
OAuth 2.0 resource provider returning an SSO Ticket to be used for authentication.
Security Warning: This resource allows exchanging an Access Token for an SSO Ticket which may provide much more access than intended. This implies that everyone in possession of an access token can impersonate the user.
The ticket only contains the username and the static roles.
This plugin is intended to be used as login_hint parameter in OpenID Connect flows and requires a configured "OpenID Connect SSO Ticket Login Hint" on the authorization server.
ticketLifetimeInSeconds) The SSO ticket lifetime in seconds.
This should be configured as short as possible.
encoder) staticRoles) identifier) condition) This resource value will only be added to the response if the configured condition is satisfied.
If no condition is configured, the resource value will always be added.
type: OAuth2SsoTicketResourceProvider
id: OAuth2SsoTicketResourceProvider-xxxxxx
displayName:
comment:
properties:
condition:
encoder:
identifier:
staticRoles:
ticketLifetimeInSeconds: 10