Subject Token Unsigned Claims Extractor
Description
Requires a subject token to be present in the token exchange request, but does not check the signature.
Tokens are expected to have at least the following claims: iss sub. If present, the claims exp and nbf are validated.
Caution: JWT tokens with alg=none are accepted: This may be a security risk.
Caution: JWT tokens with alg=none are accepted: This may be a security risk.
May be used by
Properties
Allowed Token Issuers (
allowedTokenIssuers) Description
Only tokens issued by these issuers can be exchanged at the endpoint. If left empty, all issuers are allowed.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)
type: OAuth2SubjectTokenUnsignedClaimsExtractor
id: OAuth2SubjectTokenUnsignedClaimsExtractor-xxxxxx
displayName:
comment:
properties:
allowedTokenIssuers: