← Back to plugin index

JWT Scope Handling

Description

Defines the "scope" token exchange response parameter and issued JWT claim.

Note: The order of the scope tokens that define the scope is not defined and thus may vary for every exchange. The meaning of a scope is independent of the order of the scope tokens (see RFC6749). Furthermore, adding a scope token more than once has no effect on the scope value.

Type name
OAuth2TokenExchangeJwtScopeHandling
Class
com.airlock.iam.oauth2.application.configuration.tokenexchange.rules.jwt.OAuth2TokenExchangeJwtScopeHandlingConfig
May be used by
License-Tags
OAuthTokenExchange
Properties
Scope Processors (scopeProcessors)
Description

List of scope processors that define the issued scopes.

The issued scopes are determined by successively applying each scope processor to the scopes issued by the previous one. The first scope processor in the list is applied to an empty set.

Attributes
Plugin-List
Mandatory
Assignable plugins
Scope Policy (scopePolicy)
Description

The scope policy defines how the scopes produced by the scope processors are processed.

Depending on the selected policy, the following rules apply:

  • Scopes Mandatory: It is mandatory for the scope processors to return at least one scope, otherwise the request is denied.
    • For static clients for which 'Filter Requested Scopes' is enabled: the returned scopes are filtered against the client's allowed scopes and if the client has no allowed scopes, this is treated as if the scope processors had not returned any scopes at all.
    • For static clients for which 'Filter Requested Scopes' is disabled: the returned scopes are not filtered (i.e. all scopes are allowed).
    • For persisted clients, the allowed scopes to return are stored per client and it can be configured there what the effect of an empty list of allowed scopes is.
  • Empty Scopes Allowed: It is optional for scope processors to return scopes.
    If scopes are returned:
    • For static clients for which 'Filter Requested Scopes' is enabled: the returned scopes are filtered against the client's allowed scopes and if the client has no allowed scopes, this is treated as if the scope processors had not returned any scopes at all.
    • For static clients for which 'Filter Requested Scopes' is disabled: the returned scopes are not filtered (i.e. all scopes are allowed).
    • For persisted clients, the allowed scopes to return are stored per client and it can be configured there what the effect of an empty list of allowed scopes is.
  • Always Overwrite Scopes: The scopes returned by the scope processors are ignored and replaced by the default scopes of the client. If the client has no default scopes, this is treated as if the client has not requested any scopes at all.
    With this policy, the 'Filter Requested Scopes' flag of static clients is ignored.
  • Empty Scopes Overwritten: When the scope processors do not return any scopes, the request is treated as if the default scopes of this client were returned.
    If scopes are returned:
    • For static clients for which 'Filter Requested Scopes' is enabled: the returned scopes are filtered against the client's allowed scopes and if the client has no allowed scopes, this is treated as if the scope processors had not returned any scopes at all.
    • For static clients for which 'Filter Requested Scopes' is disabled: the returned scopes are not filtered (i.e. all scopes are allowed).
    • For persisted clients, the allowed scopes to return are stored per client and it can be configured there what the effect of an empty list of allowed scopes is.
Attributes
Enum
Optional
Default value
SCOPES_MANDATORY
Allow Issuing Tokens With No Scope (emptyScopeAllowed)
Description

Defines whether issuing tokens with an empty scope is allowed or not.

If this option is disabled, token exchange requests resulting in a token with an empty scope will result in an invalid request error.

Attributes
Boolean
Optional
Default value
false
Scopes As Space Separated String (scopesAsSpaceSeparatedString)
Description

When enabled, scopes in the issued token are written as space-separated string claim (as required by RFC 9086). Otherwise, the "scope" claim will be issued as a string array, even if it only contains a single value.

Note that the scopes are also directly returned in the token exchange response. Those scopes are always returned as space-separated string (irrespective of this setting) as required by the token exchange specification.

Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)

type: OAuth2TokenExchangeJwtScopeHandling
id: OAuth2TokenExchangeJwtScopeHandling-xxxxxx
displayName: 
comment: 
properties:
  emptyScopeAllowed: false
  scopePolicy: SCOPES_MANDATORY
  scopeProcessors:
  scopesAsSpaceSeparatedString: true