Part of #5194.
Implements the core RFC 8693 token-exchange grant handler in the embedded authorization server:
SubjectTokenValidator (self-issued): validates subject tokens against the AS's own JWKS
Handler implementing fosite.TokenEndpointHandler for the token-exchange grant type
act claim construction per RFC 8693 §4.1
- Scope intersection: delegated scopes are the intersection of the client's registered scopes and the subject token's granted scopes (fail-closed if the subject token carries no scope claim)
- Delegation consent:
client_id binding, with may_act claim support for explicit cross-client delegation
- Confidential-client-only; public clients rejected
- Signing algorithm allowlist excluding
none and HS-*
- RFC 8707
resource parameter support, validated against configured allowed audiences
Branch: token-delegation-1-te-handler
Part of #5194.
Implements the core RFC 8693 token-exchange grant handler in the embedded authorization server:
SubjectTokenValidator(self-issued): validates subject tokens against the AS's own JWKSHandlerimplementingfosite.TokenEndpointHandlerfor thetoken-exchangegrant typeactclaim construction per RFC 8693 §4.1client_idbinding, withmay_actclaim support for explicit cross-client delegationnoneand HS-*resourceparameter support, validated against configured allowed audiencesBranch:
token-delegation-1-te-handler