← Back to plugin index

OAuth 2.0 Dynamic Client Registration

Description

Service for OAuth 2.0 Dynamic Client Registration Protocol that can be used for the most common use cases.

Dynamic Client Registration uses the following endpoint: /<loginapp-uri>/rest/public/tech-client-registration/oauth2/<as-identifier>/register

Type name
DefaultOAuth2ClientRegistration
Class
com.airlock.iam.techclientreg.application.configuration.oauth2dcr.DefaultOAuth2ClientRegistrationConfig
May be used by
License-Tags
TechClientRegistration
Properties
Client ID (clientIdGenerator)
Description
Defines how the client_id is determined. It can either be generated or taken from a request parameter.
Attributes
Plugin-Link
Optional
Assignable plugins
Client Secret Generator (clientSecretGenerator)
Description
Generator for the client_secret. The client secret is only generated, if this property is configured and the determined token_endpoint_auth_method is either "client_secret_basic" or "client_secret_post".
In addition, a "Token Endpoint Auth Method Processor" is required to determine the authentication method.
Attributes
Plugin-Link
Optional
Assignable plugins
Attribute Processors (additionalProcessors)
Description
Processors that handle the attributes of the registration request (other than the requested grants). Only attributes for which a processor is configured here are handled; all other aspects of the registration request are ignored.
Attributes
Plugin-List
Optional
Assignable plugins
Return Technical Client ID (returnTechClientId)
Description

If enabled, the technical client ID is included in the registration response.

The technical client ID is not identical to the client ID that is also sent with the response. The technical client ID can be used to further administer the newly created client, e.g. via Adminapp REST API.

Attributes
Boolean
Optional
Default value
false
Authorization Code Grant (authorizationCodeGrant)
Description

If enabled, Authorization Code Grant is supported.

The registered client will be enabled to perform the authorization code grant in any of the following cases:

  • If the "grant_types" requested by the client include "authorization_code". In this case a "redirect_uri" must be present.
  • If the requested "response_types" include "code". In this case a "redirect_uri" must be present.
  • If the client requests no "grant_types" and no "response_types", but supplies a "redirect_uri".
The "grant_types" of the registered client will include "authorization_code" and the "response_types" will include "code".

If this property is disabled, authorization code grant is never enabled for the client.

Note: this is not enforced at runtime. Whether the resulting client can actually use this grant is governed solely by the Authorization Server's own grant configuration, which applies identically to every client regardless of DCR registration.

Attributes
Boolean
Optional
Default value
true
Implicit Grant (implicitGrant)
Description

If enabled, Implicit Grant is supported.

The registered client will be enabled to perform implicit grant in any of the following cases:

  • If the "grant_types" requested by the client include "implicit". In this case, a "redirect_uri" must be present.
  • If the requested "response_types" include "token". In this case, a "redirect_uri" must also be present.
  • If the client requests no "grant_types" and no "response_types", but supplies a "redirect_uri".
The "grant_types" of the registered client will include "implicit" and the "response_types" will include "token".

If this property is disabled, implicit grant is never enabled for the client.

Note: this is not enforced at runtime. Whether the resulting client can actually use this grant is governed solely by the Authorization Server's own grant configuration, which applies identically to every client regardless of DCR registration.

Attributes
Boolean
Optional
Default value
false
Client Credentials Grant (clientCredentialsGrant)
Description

If enabled, Client Credentials Grant is supported.

The registered client will be enabled to perform client credentials grant in any of the following cases:

  • If the "grant_types" requested by the client include "client_credentials".
  • If the client specifies no "grant_types" in the registration request.

If this property is disabled, client credentials grant is never enabled for the client.

Note: this is not enforced at runtime. Whether the resulting client can actually use this grant is governed solely by the Authorization Server's own grant configuration, which applies identically to every client regardless of DCR registration.

Attributes
Boolean
Optional
Default value
false
Access Token Refresh (accessTokenRefresh)
Description

If enabled, refreshing an access token is supported.

The registered client will be enabled to refresh access tokens in any of the following cases:

  • If the "grant_types" requested by the client include "refresh_token".
  • If the client specifies no "grant_types" in the registration request.

If this property is disabled, refreshing of access tokens is never enabled for the client.

Note: this is not enforced at runtime. Whether the resulting client can actually use this grant is governed solely by the Authorization Server's own grant configuration, which applies identically to every client regardless of DCR registration.

Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)

type: DefaultOAuth2ClientRegistration
id: DefaultOAuth2ClientRegistration-xxxxxx
displayName: 
comment: 
properties:
  accessTokenRefresh: true
  additionalProcessors:
  authorizationCodeGrant: true
  clientCredentialsGrant: false
  clientIdGenerator:
  clientSecretGenerator:
  implicitGrant: false
  returnTechClientId: false