← Back to plugin index

OIDC Discovery Actor Token Validation

Description

Actor token validation based on OpenID Connect discovery.

Requires an actor token to be present in the token exchange request, and checks the signature using the issuer's OIDC endpoints. Tokens are expected to have at least the following claims: iss, sub, exp. The token must not be expired.

Type name
OAuth2OIDCDiscoveryActorTokenValidation
Class
com.airlock.iam.oauth2.application.configuration.tokenexchange.rules.jwt.OAuth2OIDCDiscoveryActorTokenValidationConfig
May be used by
Properties
Allowed Token Issuers (allowedTokenIssuers)
Description
Only tokens issued by these issuers can be exchanged at the endpoint.
Attributes
Plugin-List
Mandatory
Assignable plugins
HTTP Client (httpClient)
Description
The HTTP client used to fetch the JWKS data.
Attributes
Plugin-Link
Optional
Assignable plugins
Cache Refresh Time [minutes] (cacheRefreshTimeInMinutes)
Description
Time in minutes after which cached data from the discovery endpoint URL and the JWKS URL is refreshed.

The refresh is asynchronous: the first request after this time still receives the previously cached data and triggers a reload in the background.

Subsequent requests receive the refreshed data.

Data not requested for twice this time expires and is reloaded synchronously on the next request, so served data is never older than twice this time.

The JWKS data is additionally reloaded if a key is not yet known, or if a signature check with a known key fails.

If a refresh fails, the previously fetched data is kept while the entry is still in use.

Attributes
Integer
Optional
Default value
2880
YAML Template (with default values)

type: OAuth2OIDCDiscoveryActorTokenValidation
id: OAuth2OIDCDiscoveryActorTokenValidation-xxxxxx
displayName: 
comment: 
properties:
  allowedTokenIssuers:
  cacheRefreshTimeInMinutes: 2880
  httpClient: