← Back to plugin index

Actor Token Unsigned Claims Extractor

Description
Requires an actor token to be present in the token exchange request, but does not check the signature. Tokens are expected to have at least the following claims: iss sub. If present, the claims exp and nbf are validated.
Caution: JWT tokens with alg=none are accepted: This may be a security risk.
Type name
OAuth2ActorTokenUnsignedClaimsExtractor
Class
com.airlock.iam.oauth2.application.configuration.tokenexchange.rules.jwt.OAuth2ActorTokenUnsignedClaimsExtractorConfig
May be used by
License-Tags
OAuthTokenExchange
Properties
Allowed Token Issuers (allowedTokenIssuers)
Description
Only tokens issued by these issuers can be exchanged at the endpoint. If left empty, all issuers are allowed.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: OAuth2ActorTokenUnsignedClaimsExtractor
id: OAuth2ActorTokenUnsignedClaimsExtractor-xxxxxx
displayName: 
comment: 
properties:
  allowedTokenIssuers: