Authenticated Client ID (OAuth 2.0 Token Exchange)
Description
Sets the act claim to a claim set containing the authenticated client ID as sub claim and nests the original act claim from the subject token data into this claim set.
Nesting the act claim within another expresses a chain of delegation. The outermost act claim represents the current actor while nested act claims represent prior actors. The least recent actor is the most deeply nested. The nested act claims serve as a history trail that connects the initial request and subject through the various delegation steps undertaken before reaching the current actor.
If the subject token data has no act claim, the new claim only contains the sub claim.
May be used by
Properties
YAML Template (with default values)
type: OAuth2TokenExchangeAuthenticatedClientIdActorClaim
id: OAuth2TokenExchangeAuthenticatedClientIdActorClaim-xxxxxx
displayName:
comment:
properties: