OIDC Discovery Subject Token Validation
Subject token validation based on OpenID Connect discovery.
The subject token "iss" claim will be checked against the list of allowed token issuers and used to determine the OIDC discovery endpoint (see the OIDC discovery specifications). The JWKS keys obtained through OIDC discovery at that URL will then be used for the subject token signature validation.
allowedTokenIssuers) httpClient) cacheRefreshTimeInMinutes) The refresh is asynchronous: the first request after this time still receives the previously cached data and triggers a reload in the background.
Subsequent requests receive the refreshed data.
Data not requested for twice this time expires and is reloaded synchronously on the next request, so served data is never older than twice this time.
The JWKS data is additionally reloaded if a key is not yet known, or if a signature check with a known key fails.
If a refresh fails, the previously fetched data is kept while the entry is still in use.
type: OAuth2OIDCDiscoverySubjectTokenValidation
id: OAuth2OIDCDiscoverySubjectTokenValidation-xxxxxx
displayName:
comment:
properties:
allowedTokenIssuers:
cacheRefreshTimeInMinutes: 2880
httpClient: