Add Scope From Subject Token
Description
Will add the scopes from the subject token's "scope" data.
If the subject token's "scope" data is string-valued, it is parsed as an OAuth 2.0 access token scope as defined in RFC6749. If the subject token's "scope" data is string-valued but its format does not conform with the specification, it will be ignored.
If the subject token's "scope" data is a string array, each value is parsed as a single OAuth 2.0 scope value as defined in RFC6749. If the subject token's "scope" data is an array but any of its values is not a string or does not conform with the specification, the whole array will be ignored.
If the subject token's "scope" data is not present, is neither a string nor a string array, or is an empty array, it will be ignored.
May be used by
Properties
Add only scopes matching (
patterns) Description
An optional list of regular expressions. If the list is configured, only scope values matching any of the regular expressions will be added. Scope values that do not match any of the configured regular expressions will be ignored. If the list is not configured, all the scope values will be added.
Attributes
RegEx-List
Optional
YAML Template (with default values)
type: OAuth2TokenExchangeSubjectTokenScopeProcessor
id: OAuth2TokenExchangeSubjectTokenScopeProcessor-xxxxxx
displayName:
comment:
properties:
patterns: