Skip to content

Add RFC 8693 token exchange handler to the embedded AS #5812

Description

@jhrozek

Part of #5194.

Implements the core RFC 8693 token-exchange grant handler in the embedded authorization server:

  • SubjectTokenValidator (self-issued): validates subject tokens against the AS's own JWKS
  • Handler implementing fosite.TokenEndpointHandler for the token-exchange grant type
  • act claim construction per RFC 8693 §4.1
  • Scope intersection: delegated scopes are the intersection of the client's registered scopes and the subject token's granted scopes (fail-closed if the subject token carries no scope claim)
  • Delegation consent: client_id binding, with may_act claim support for explicit cross-client delegation
  • Confidential-client-only; public clients rejected
  • Signing algorithm allowlist excluding none and HS-*
  • RFC 8707 resource parameter support, validated against configured allowed audiences

Branch: token-delegation-1-te-handler

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions