Configure client_id as mandatory param for password grant type

Viewed 70

What is the proper way to make client_id a mandatory param for password grant type? Using this request I want to make client_id a mandatory value and let the OAuth2 framework to compare it with the result returned into the method loadClientByClientId

curl --location --request POST 'http://localhost:8080/engine/oauth/token' \
--header 'Authorization: Basic YWRtaW46cXdlcnR5' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'username=admin' \
--data-urlencode 'password=qwerty' \
--data-urlencode 'client_id=some_value' \
--data-urlencode 'grant_type=password' \
--data-urlencode 'scope=read_profile'

What is the best way to implement this?

1 Answers

You could try implementing a custom OAuth2RequestValidator with method validateScope(TokenRequest tokenRequest, ...) from the docs

Ensure that the client has requested a valid set of scopes.

which has access to TokenRequest.getRequestParameters()

EDIT See also the docs for the TokenEndpoint

Clients must be authenticated (...) to access this endpoint, and the client id is extracted from the authentication token. (...)

Related