Flow Condition-based OAuth 2.0 Scope Condition
Description
Configures a OAuth 2.0 scope condition.
The scope is matched against the "Scope Matcher" pattern. A scope is allowed if it matches the regex and the condition is fulfilled.
May be used by
Properties
Scope Matcher (
scopeMatcher) Description
Matches the scope to check.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Condition (
condition) Description
The condition that must be fulfilled. If the condition is not fulfilled, the scope is restricted and thus can not be granted.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Account Linking Required Red Flag Condition Active Authentication Method Airlock 2FA Device Deletion Possible Airlock 2FA was used for login (Transaction Approval only) Always False Always True Boolean Condition Cronto Activation Possible Cronto Activation Required Cronto Device Removal Possible Cronto Letter Order Condition Cronto was used for login (Transaction Approval only) CrontoSign Swiss Push Activation Possible Email OTP was used for login (Transaction Approval only) FIDO Credential Removal Possible FIDO was used for login (Transaction Approval only) First Usage of Device Has Cronto Account Has Cronto Device Has Device Token Has Email Address Has FIDO Credential Has Matching Role Has Matrix Card Has OATH OTP Token Has Password Has Suitable Airlock 2FA Device Has Tag Has Vasco OTP Token Has mTAN Activation Letter Has mTAN Token IdP-Initiated SSO Flow On SP Logical AND Logical NOT Logical OR Matching Username Never Migrate Possible New Device Condition Next Authentication Method-based Migration Condition OAuth 2.0 Authorization Code Grant In Progress OIDC prompt=none Condition Password Letter Order Interval Condition Public Self-Service Allowed Condition Red Flag Raised Request Has SSO Ticket Step Activated String Regex Condition User Attribute Is Unique User Identified User Represented Condition Vasco Activation Possible mTAN Number Changed mTAN Number Deletion Possible mTAN Number Registration Possible mTAN was used for login (Transaction Approval only)
YAML Template (with default values)
type: FlowConditionBasedOAuth2ScopeCondition
id: FlowConditionBasedOAuth2ScopeCondition-xxxxxx
displayName:
comment:
properties:
condition:
scopeMatcher: