Simple OAuth Token Exchange
Implements the OAuth 2.0 Token Exchange (RFC 8693) for the Simple OAuth module.
Key Features
- Allows for exchanging an existing access token for another one with different scopes
- Provides a new grant type for Token Exchange
- Useful when a token with a narrower scope is needed for another context in the same client
Example Use Case
Given a frontend application that uses BFF (Backend for Frontend) to communicate with Drupal. The BFF holds the access token with all needed privileges for the user to interface with Drupal.
But in some scenarios, like handling large file uploads, proxying the upload through the BFF might not be preferred or even possible (e.g. Vercel Serverless Functions have a max body size of 4.5 MB).
In such a case a new access token with only the scope permitting the file upload can be requested using the existing access token from the BFF. This access token can then be given to the browser to be used in the file upload.
Depends on
Dependencies of the latest stable release
No dependencies recorded for this project.
Required by
Tracked projects that depend on this one
No tracked projects depend on this one yet.