OAUTH 2.0 · LAB
Read a client registration as a set of rules
Map each line of the printer's registration to a request it allows or refuses, suspend one client without affecting its sibling, and see that a client ID means something only to its issuer.
ReadyUses your lab tenant
The lesson
Builds on: Choosing a flow.
New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.
Your progress
Press Start before you begin. Only events your tenant records after that count, in the order below. Checking reads your tenant's Audit, so you need Audit read access in it.
Sign in to start this lab and check your progress. Log in or create an account.
A scope outside the registration is refused
Recorded as
oauth.tokenrejected (invalid_scope) forlab-print-orders.Suspend the printer
Recorded as
tenant.oauth.clients.updatesucceeded.The suspended printer cannot authenticate
Recorded as
oauth.tokenrejected (client_disabled) forlab-printer.The printer's public app keeps working
Recorded as
oauth.tokensucceeded forlab-printer-app.Re-enable the printer
Recorded as
tenant.oauth.clients.updatesucceeded.
Request console
Requests in this lab can be sent from this page to your tenant: open one and choose Send. Fill in the values below first. They stay in this page's memory and are gone when you leave; secrets are never stored or sent anywhere except the request you send.
Setup
Set the shell variables:
ISSUER,PRINTER_IDandPRINTER_SECRETforlab-printer,ORDERS_IDandORDERS_SECRETforlab-print-orders,APP_IDforlab-printer-app,API_IDandAPI_SECRETforlab-photo-api, andenc.Get a current printer access token for Ava with the code flow from the authorization code labs, and keep it as
TOKEN.Press Start on this page.
Walkthrough
Open OAuth > Clients > lab-printer > View and write its registration in the lesson's format. Read the authentication method from discovery's
token_endpoint_auth_methods_supported.
Client ID: <generated by the tenant, not chosen>
Client type: confidential
Redirect URIs: http://127.0.0.1:8765/callback, https://beyondthelogin.dev/lab/callback/
Grant types: authorization_code, refresh_token
Scopes it may request: every common scope (Restrict scopes is off)
Client authentication: client_secret_basic
Do the same for lab-print-orders: confidential, no redirect URIs, client_credentials, only prints.create (Restrict scopes is on), client_secret_basic.
Why it matters: each line is a rule the authorization server applies to every later request, not paperwork.
Turn lines into requests that fall outside them.
Grant type: client credentials as the printer answers
unauthorized_client, as in the Choosing a flow lab.Redirect URI: an authorization request for the printer with
https://beyondthelogin.dev/lab/callback(no trailing slash) stops on the tenant's error page.Scopes:
curl -s -u "$ORDERS_ID:$ORDERS_SECRET" -d grant_type=client_credentials -d scope=photos.read "$ISSUER/oauth/token" | jqanswersinvalid_scope. This server rejects the request rather than silently dropping the scope.
Why it matters: a request outside the registration never reaches consent, policy or the API.
Suspend one client. Open OAuth > Clients > lab-printer > Edit, untick Enabled and save. The editor warns that saving revokes the client's tokens, codes and remembered consent.
An authorization request for the printer stops on the tenant's error page.
Client authentication as the printer, for example
curl -s -i -u "$PRINTER_ID:$PRINTER_SECRET" -d grant_type=refresh_token -d refresh_token=x "$ISSUER/oauth/token", answers401 invalid_client, "Client authentication failed. Check the client ID and secret, and that the client is enabled."btl-lab introspect "$TOKEN"answers{"active": false}for the token issued before the change.
The sibling keeps working. Run the public app's loopback flow from the Public and confidential clients lab with
lab-printer-app, as Ava. It succeeds.
Why it matters: one registration per deployment lets the photo service suspend exactly the client that misbehaves, without breaking its siblings.
Re-enable the printer: tick Enabled and save.
TOKENstays inactive. Turning a client on restores nothing it lost.
Restore: confirm lab-printer shows Enabled.
Optional, with Lab Mail: use
PRINTER_IDin an authorization request to$ISSUER2. It stops on that tenant's error page as an unknown client. The ID means something only to the issuer that created it.
Registration through an API is not offered here yet.
POST$ISSUER/oauth/register
Open in console
POST $ISSUER/oauth/register HTTP/1.1
Content-Type: application/json
{}The answer is 501. Clients in this tenant are created by an administrator; dynamic registration is gap G9.
Break it
Step 3 is the deliberate suspension, and step 5 restores it.
Check your work
Press Check my progress. Logs also has oauth.authorize rejected invalid_client for the suspended client's authorization request, and oauth.register rejected not_implemented with status 501.
Cleanup
Confirm
lab-printeris Enabled.
There is no list yet of the people who connected a client (G40). Changing a client's settings clears its remembered consent instead.