New-R1TokenValidator
New-R1TokenValidator
SYNOPSIS
Creates an external token validator.
SYNTAX
New-R1TokenValidator [-name] <String> [-jsonWebKeySetUri] <String> [[-enabled] <Boolean>]
[[-apiService] <String>] [[-oidcProvider] <String>] [[-oidcDiscoveryUrl] <String>]
[[-scopeClaimName] <String>] [[-expectedAudience] <String>] [[-expectedScope] <String>]
[[-jwtValidationClock] <Int32>] [[-claimsExpressionList] <String[]>] [-WhatIf] [-Confirm] [<CommonParameters>]
DESCRIPTION
Creates an external token validator, which accepts tokens issued by an external OIDC provider for either the ADAP REST API or SCIM.
The API defines two variants discriminated by apiService, but they carry identical properties, so one command covers both.
EXAMPLES
Example 1
$Validator = @{
name = 'partner-idp'
jsonWebKeySetUri = 'https://idp.example.com/jwks'
enabled = $true
apiService = 'SCIM'
oidcProvider = 'partner'
oidcDiscoveryUrl = 'https://idp.example.com/.well-known/openid-configuration'
scopeClaimName = 'scope'
expectedAudience = 'radiantone'
expectedScope = 'scim'
jwtValidationClock = 30
claimsExpressionList = 'uid=$sub'
}
New-R1TokenValidator @Validator
Creates a SCIM token validator, giving every property as the control panel does. A create giving only the name and key set is refused.
PARAMETERS
-Confirm
Prompts you for confirmation before running the cmdlet.
Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-WhatIf
Shows what would happen if the cmdlet runs. The cmdlet is not run.
Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-apiService
The API the validator applies to. REST(adap) or SCIM.
Type: String
Parameter Sets: (All)
Aliases:
Accepted values: REST(adap), SCIM
Required: False
Position: 3
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-claimsExpressionList
The claims mapping expressions. The API nests these in a claimsMapper object, which this command builds, so the expressions are given directly.
Type: String[]
Parameter Sets: (All)
Aliases:
Required: False
Position: 10
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-enabled
Whether the validator is enabled.
Type: Boolean
Parameter Sets: (All)
Aliases:
Required: False
Position: 2
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-expectedAudience
The audience a token must carry to be accepted.
Type: String
Parameter Sets: (All)
Aliases:
Required: False
Position: 7
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-expectedScope
The scope a token must carry to be accepted.
Type: String
Parameter Sets: (All)
Aliases:
Required: False
Position: 8
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-jsonWebKeySetUri
The JSON web key set URI used to verify token signatures.
Type: String
Parameter Sets: (All)
Aliases:
Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-jwtValidationClock
Clock skew allowed when validating a token, in seconds, up to 3600.
Type: Int32
Parameter Sets: (All)
Aliases:
Required: False
Position: 9
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-name
The name of the external token validator.
Type: String
Parameter Sets: (All)
Aliases:
Required: True
Position: 0
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-oidcDiscoveryUrl
The OIDC discovery document URL of the provider.
Type: String
Parameter Sets: (All)
Aliases:
Required: False
Position: 5
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-oidcProvider
The OIDC provider the tokens come from. Apple, Google, Microsoft, Salesforce, Yahoo or Custom. Values other than Custom are retained for legacy reasons and are converted to Custom by the API.
Type: String
Parameter Sets: (All)
Aliases:
Accepted values: Apple, Google, Microsoft, Salesforce, Yahoo, Custom
Required: False
Position: 4
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-scopeClaimName
The name of the claim holding the token scopes.
Type: String
Parameter Sets: (All)
Aliases:
Required: False
Position: 6
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
INPUTS
System.String
System.Boolean
System.Int32
System.String[]
OUTPUTS
System.Void
NOTES
The API rejects a create which carries only some of the validator’s properties, answering “Cannot convert request body to required type” and creating nothing. The control panel sends every one of -name, -enabled, -oidcProvider, -oidcDiscoveryUrl, -jsonWebKeySetUri, -jwtValidationClock, -scopeClaimName, -expectedAudience, -apiService, -expectedScope and -claimsExpressionList.
Which of them the API insists on has not been established.