Actor Token Unsigned Claims Extractor
Description
Requires an actor token to be present in the token exchange request, but does not check the signature.
Tokens are expected to have at least the following claims: iss sub. If present, the claims exp and nbf are validated.
Caution: JWT tokens with alg=none are accepted: This may be a security risk.
Caution: JWT tokens with alg=none are accepted: This may be a security risk.
May be used by
Properties
Allowed Token Issuers (
allowedTokenIssuers) Description
Only tokens issued by these issuers can be exchanged at the endpoint. If left empty, all issuers are allowed.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)
type: OAuth2ActorTokenUnsignedClaimsExtractor
id: OAuth2ActorTokenUnsignedClaimsExtractor-xxxxxx
displayName:
comment:
properties:
allowedTokenIssuers: