OAuthClientEndpoint
OAuth client endpoint configuration allows to create and edit configuration settings for local OAuth Client FEPs that represent the client side of the OAuth communication.
Context path
The context path of the web application. If not specified, the context path is set to the default 'unknown' value.
Do exclude from authorization
Whether or not the web application shall be excluded from authorization process defined by the DirX Access PEP.
Port assignment identifiers
Identifiers of the port assignments for the web application. Port assignments specify the HTTP(S) ports on which the web application will listen.
Primary port assignment identifier
Identifier of the primary port assignment for given web application. It can be used for calculation of the FEP location, if location is not specified.
CORS parameters
Additional CORS parameters to those already generated from the existing endpoint configuration. CORS parameters are used to filter CORS requests.
Allowed origins
Origins allowed in the Origin header when filtering CORS requests. This
parameter has to be combined with 'allowedMethods' and 'allowedHeaders'.
According to the CORS specification, the Origin header can contain the
string null. It is possible to include this string in this
configuration property with following meaning:
-
without
nullincluded - Origin headernullleads to response FORBIDDEN, -
with
nullincluded - Origin headernullleads to request being further processed, -
*enables also thenullstring.
Associated Web PEP identifier
The identifier of the Web PEP that enforces the security policy at the endpoint.
OAuth authentication method identifier
The authentication method to be used for authenticating the user.
Default partnership (client) metadata identifier
The value used when a request to the OAuth Client FEP does not contain a partnership identifier.
OAuth Server metadata update interval
The interval (seconds) at which OAuth Server metadata are reloaded. OAuth Server metadata with a configured URL are periodically reloaded. Set this field to zero or a negative number to disable this feature. If a metadata URL is accessed via TLS, the WebApplications container JRE keystore is used for certificate path validation.