OIDC Discovery Actor Token Validation
Actor token validation based on OpenID Connect discovery.
Requires an actor token to be present in the token exchange request, and checks the signature using the issuer's OIDC endpoints. Tokens are expected to have at least the following claims: iss, sub, exp. The token must not be expired.
allowedTokenIssuers) httpClient) cacheRefreshTimeInMinutes) The refresh is asynchronous: the first request after this time still receives the previously cached data and triggers a reload in the background.
Subsequent requests receive the refreshed data.
Data not requested for twice this time expires and is reloaded synchronously on the next request, so served data is never older than twice this time.
The JWKS data is additionally reloaded if a key is not yet known, or if a signature check with a known key fails.
If a refresh fails, the previously fetched data is kept while the entry is still in use.
type: OAuth2OIDCDiscoveryActorTokenValidation
id: OAuth2OIDCDiscoveryActorTokenValidation-xxxxxx
displayName:
comment:
properties:
allowedTokenIssuers:
cacheRefreshTimeInMinutes: 2880
httpClient: