← Back to plugin index

Subject Token Unsigned Claims Extractor

Description
Requires a subject token to be present in the token exchange request, but does not check the signature. Tokens are expected to have at least the following claims: iss sub. If present, the claims exp and nbf are validated.
Caution: JWT tokens with alg=none are accepted: This may be a security risk.
Type name
OAuth2SubjectTokenUnsignedClaimsExtractor
Class
com.airlock.iam.oauth2.application.configuration.tokenexchange.OAuth2SubjectTokenUnsignedClaimsExtractorConfig
May be used by
License-Tags
OAuthTokenExchange
Properties
Allowed Token Issuers (allowedTokenIssuers)
Description
Only tokens issued by these issuers can be exchanged at the endpoint. If left empty, all issuers are allowed.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: OAuth2SubjectTokenUnsignedClaimsExtractor
id: OAuth2SubjectTokenUnsignedClaimsExtractor-xxxxxx
displayName: 
comment: 
properties:
  allowedTokenIssuers: