Django OpenID Connect and OAuth2.0 - Splitting Authorization Server and Resource Server

Viewed 868

I have multiple Resource Servers and one Auth Server all written in Django. I have implemented OIDC Provider in the Auth Server using Django OIDC Provider Library. So it provides OAuth 2.0 support as well.

Having OAuth 2.0 Token Introspection (RFC 7662) implemented, it allows authorized protected resources to query the authorization server to determine the set of metadata(and verification) for a given access token that was presented to them by an OAuth 2.0 client.

I'm getting trouble in setting up the Resource Server, as there's no RESOURCE_SERVER_INTROSPECTION_URL provided like other standard OAuth 2.0 providers for internally verifying the access token with Auth Server(using an internal post request to Auth Server).

For example in the Django OAuth Toolkit library, it has clearly been specified in their documentation.

But In Django OIDC Provider, they have provided a hook for that OIDC_INTROSPECTION_PROCESSING_HOOK, which I could not understand how to use. Also, there's no detail about it on their official page.

I need help in setting up my separate resource servers which can rely on my Auth Server for any token creation and verification.

I want to set up an introspect endpoint something like this in my resource server settings.py file:

OAUTH_PROVIDER = {
    ...
    'RESOURCE_SERVER_INTROSPECTION_URL': 'https://example.org/o/introspect/',
    'RESOURCE_SERVER_AUTH_TOKEN': '<Interospection Token>', 
    ...
}

or small customization in their provided default hook will also be helpful. And how to configure it to communicate with my Auth Server.

def default_introspection_processing_hook(introspection_response, client, id_token):

    # Verification Logic Here 
    return introspection_response

Any help will be much appreciated.

0 Answers
Related