← Back to plugin index

OAuth 2.0 Clean-up Task

Description

Task to clean up expired OAuth 2.0 / OpenID Connect tokens and sessions etc.

To minimize database locks, the task doesn't delete all expired items in one transaction but deletes the tokens in configurable batches.

It is recommended to schedule this task with a daily interval during a time with a low database load. Depending on the total number of tokens and the number of deletable OAuth 2.0 tokens, the task might take some time, but a proper "Batch Size" will keep row locks at a minimum.

Type name
OAuth2CleanupTask
Class
com.airlock.iam.servicecontainer.app.application.configuration.task.oauth2.OAuth2CleanupTask
May be used by
License-Tags
OAuthServer
Properties
SQL Data Source (sqlDataSource)
Description
Defines how connections to the database are obtained.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Batch Size (batchSize)
Description

During cleanup, any expired entries are deleted in batches of this size. This ensures that any row locks on the database are very short-lived and do not affect parallel modifications. This value should not be set too high to prevent very long-running transactions.

Cleanup will repeatedly delete this number of database entries until all expired tokens, sessions, pushed authorization requests and client assertions have been removed. Therefore, this task can take some time when a lot of expired items are present.

This size should be chosen such that every batch does not take longer than 5 seconds. The average runtime of the batches can be found in the task's logs.

Attributes
Integer
Optional
Default value
1000
Cleanup Pushed Authorization Requests (cleanupPushedAuthorizationRequests)
Description

If set to true, expired Pushed Authorization Requests will be removed during cleanup.

Note that if this is set to true, the database must contain an oauth2_par_request table; otherwise an exception will be thrown during cleanup.

Attributes
Boolean
Optional
Default value
true
Cleanup Accepted Client Assertions (cleanupAcceptedClientAssertions)
Description

If set to true, expired private key JWTs previously accepted as client_assertion during client authentication will be removed during cleanup.

Note that if this is set to true, the database must contain an oauth2_accepted_client_assertions table; otherwise an exception will be thrown during cleanup.

Attributes
Boolean
Optional
Default value
true
Token Table Name (tokenTableName)
Description
The name of the database table containing the tokens.
Attributes
String
Optional
Default value
token
Token Assignment Table Name (tokenAssignmentTableName)
Description
The name of the database table containing the token assignments.
Attributes
String
Optional
Default value
token_assignment
Log Queries (logQueries)
Description

If enabled, all SQL queries executed during cleanup will be written to the module's corresponding log file. This is only effective if the log level is set to at least INFO.

Warning: query values (including potentially sensitive data) will be logged as well.

Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: OAuth2CleanupTask
id: OAuth2CleanupTask-xxxxxx
displayName: 
comment: 
properties:
  batchSize: 1000
  cleanupAcceptedClientAssertions: true
  cleanupPushedAuthorizationRequests: true
  logQueries: false
  sqlDataSource:
  tokenAssignmentTableName: token_assignment
  tokenTableName: token