Sovite.SASL.Backend.Introspection (sovite v0.2.0)

Copy Markdown View Source

A Sovite.SASL.Backend for OAUTHBEARER: checks bearer tokens with OAuth 2.0 token introspection (RFC 7662) at the identity provider.

The token must be active, not expired, and carry :required_scope if set. The user name is taken from the :username_claim of the introspection response.

Options

  • :url - the introspection endpoint. Required.
  • :client_id / :client_secret - credentials for the endpoint, sent with HTTP Basic authentication.
  • :username_claim - defaults to "username". Common alternatives are "email" and "preferred_username".
  • :required_scope - a scope the token must have.
  • :timeout - milliseconds. Defaults to 10 seconds.
  • :cacerts - CAs to verify an https endpoint against. Defaults to the system's.