← Back to plugin index

OIDC Discovery Subject Token Validation

Description

Subject token validation based on OpenID Connect discovery.

The subject token "iss" claim will be checked against the list of allowed token issuers and used to determine the OIDC discovery endpoint (see the OIDC discovery specifications). The JWKS keys obtained through OIDC discovery at that URL will then be used for the subject token signature validation.

Type name
OAuth2OIDCDiscoverySubjectTokenValidation
Class
com.airlock.iam.oauth2.application.configuration.tokenexchange.OAuth2OIDCDiscoverySubjectTokenValidationConfig
May be used by
License-Tags
OAuthTokenExchange
Properties
Allowed Token Issuers (allowedTokenIssuers)
Description
Only tokens issued by these issuers can be exchanged at the endpoint.
Attributes
Plugin-List
Mandatory
Assignable plugins
HTTP Client (httpClient)
Description
The HTTP client used to fetch the JWKS data.
Attributes
Plugin-Link
Optional
Assignable plugins
Cache Refresh Time [minutes] (cacheRefreshTimeInMinutes)
Description
Time in minutes after which cached data from the discovery endpoint URL and the JWKS URL is refreshed.

The refresh is asynchronous: the first request after this time still receives the previously cached data and triggers a reload in the background.

Subsequent requests receive the refreshed data.

Data not requested for twice this time expires and is reloaded synchronously on the next request, so served data is never older than twice this time.

The JWKS data is additionally reloaded if a key is not yet known, or if a signature check with a known key fails.

If a refresh fails, the previously fetched data is kept while the entry is still in use.

Attributes
Integer
Optional
Default value
2880
YAML Template (with default values)

type: OAuth2OIDCDiscoverySubjectTokenValidation
id: OAuth2OIDCDiscoverySubjectTokenValidation-xxxxxx
displayName: 
comment: 
properties:
  allowedTokenIssuers:
  cacheRefreshTimeInMinutes: 2880
  httpClient: