Audience From Subject Token (OAuth 2.0 Token Exchange)
Sets the claim value to that of the subject token's "aud" claim value.
If present, the subject token's "aud" data is parsed as either a single string audience value or an array of string audience values as per RFC7519. If the subject token's "aud" data is present but does not conform with the specification, the token exchange request will lead to an invalid request error.
If the subject token's "aud" data is single-valued after removing non-allowed values (i.e. it is either a string or an array with a single element after removing the values not matching any of the configured patterns) and conforms with the specification, the claim value will be set to a string. If the subject token's "aud" data is multi-valued and conforms with the specification, the claim value will be set to an array.
If the subject token's "aud" data is not present, is an empty array or none of the values match the configured filters, the claim value will not be set.
valueFilters) An optional list of regular expressions. If the list is configured, only values in in the subject token's "aud" data matching at least one of the regular expressions will be added. Values that do not match any of the configured regular expressions will be ignored. If the list is not configured, all the values in the subject token's "aud" claim will be added.
type: OAuth2TokenExchangeJwtSubjectTokenAudienceClaimValue
id: OAuth2TokenExchangeJwtSubjectTokenAudienceClaimValue-xxxxxx
displayName:
comment:
properties:
valueFilters: