← Back to plugin index

OAuth 2.0 SSO Ticket Resource

Description

OAuth 2.0 resource provider returning an SSO Ticket to be used for authentication.

Security Warning: This resource allows exchanging an Access Token for an SSO Ticket which may provide much more access than intended. This implies that everyone in possession of an access token can impersonate the user.

The ticket only contains the username and the static roles.

This plugin is intended to be used as login_hint parameter in OpenID Connect flows and requires a configured "OpenID Connect SSO Ticket Login Hint" on the authorization server.

Type name
OAuth2SsoTicketResourceProvider
Class
com.airlock.iam.oauth2.application.configuration.resource.OAuth2SsoTicketResourceProviderConfig
May be used by
License-Tags
OAuthServer
Properties
Ticket Lifetime [s] (ticketLifetimeInSeconds)
Description

The SSO ticket lifetime in seconds.

This should be configured as short as possible.

Attributes
Integer
Optional
Default value
10
Encoder (encoder)
Description
The ticket encoder plugin used to sign and encrypt the SSO ticket.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Static Roles (staticRoles)
Description
Static list of roles granted to the user in the ticket. Can be used to assign special roles to the user, for example for Step-Up scenarios.
Attributes
String-List
Optional
Identifier (identifier)
Description
The identifier of this resource provider.
Attributes
String
Mandatory
Example
user
Example
language
Condition (condition)
Description

This resource value will only be added to the response if the configured condition is satisfied.

If no condition is configured, the resource value will always be added.

Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: OAuth2SsoTicketResourceProvider
id: OAuth2SsoTicketResourceProvider-xxxxxx
displayName: 
comment: 
properties:
  condition:
  encoder:
  identifier:
  staticRoles:
  ticketLifetimeInSeconds: 10