OAuth2Provider.properties revision 54b9bd7372729ef711367142ec1308dd4237b18e
1224N/Ag101.help=The maximum execution time any individual script should take on the server (in seconds).
1224N/Ag101.help.txt=Scripts will be forcibly stopped after this amount of execution time.
1224N/Ag103.help.txt=New threads will be created up to this size once the task queue reaches capacity. Has no effect if the \
1224N/Ag104.help=Size of queue to use for buffering script execution request when core pool is at capacity.
4134N/Ag104.help.txt=Use -1 for an unbounded queue (this disables the maximum pool size setting). For short, CPU-bound \
1211N/A scripts, consider a small pool size and larger queue length. For I/O-bound scripts (e.g., REST calls) consider \
2086N/A a larger maximum pool size and a smaller queue. Not hot-swappable: restart server for changes to take effect.
1211N/Ag105.help.txt=Length of time (in seconds) to wait before terminating threads that were started when the queue reached \
1211N/Ag106.help.txt=Each Java class accessed by a script must match at least one of these patterns. Use '*' as a wildcard, \
1211N/Ag107.help.txt=This blacklist is applied after the whitelist to apply additional restrictions. For instance you may \
1211N/A whitelist java.lang.* and then blacklist java.lang.System and java.lang.Runtime. It is recommended to always prefer \
1211N/Ag108.help=Indicates whether the system SecurityManager should also be consulted when checking access to Java classes.
1211N/Ag108.help.txt=If enabled, then the checkPackageAccess method will be called for each Java class accessed. If no \
1211N/Aa103a.help=Check to enable generation of refresh tokens when refreshing access tokens
1224N/Aa104aa.help=This is a script that will be run, when using an implementation of the \
1211N/A org.forgerock.openam.oauth2.OpenAMScopeValidator, when issuing an ID Token or making a request to the userinfo \
1211N/A endpoint that will gather and fill in all claims for the request. The script has access to the requested scopes, \
1211N/Aa104ab.help=This is the language of the OIDC claims script
1211N/Aa105.help=Response types are input as such, code|name of plugin class. For example, code|org.forgerock.openam.oauth2.CodeClass. \
1211N/AIf there is no implementation class none should be used in place of the class name. For example id_token|none.
1211N/Aa106.help=If the attribute is mail and uid, then a search string of (|(mail=user)(uid=user)) will be used to get the \
1211N/Aa107.help=To use saved consent a list attribute must be set up and the attribute name provided.
1211N/Aa110.help=List of subject types supported. Values are pairwise and public. Pairwise is the same as confidential.
1211N/Aa114.help=The name of the key put in the keystore used to sign the ID Tokens issued by OpenAM.
2086N/Aa115.help=Allow clients to register without an access token. If enabled, you should consider adding some form of rate \
1211N/A limiting. See <a href="http://openid.net/specs/openid-connect-registration-1_0.html#ClientRegistration" \
1211N/Aa116.help=Whether to generate Registration Access Tokens for clients that register via open dynamic client \
1224N/A href="http://openid.net/specs/openid-connect-registration-1_0.html#ClientConfigurationEndpoint" \
1224N/A target="_blank">Client Configuration Endpoint</a> as per the OpenID Connect specification. This setting has \
1224N/A href="http://openid.net/specs/openid-connect-core-1_0.html#AuthRequest" target="_blank">the acr_values parameter</a> \
1224N/Aa118.help=Default value to use as the 'acr' claim in an OpenID Connect ID Token when using the default authentication \
1224N/Aa119.help=If you require <code>amr</code> values to be returned in the OpenID Connect <code>id_token</code>, you can \
1224N/A configure them here. Once authentication has completed, the authentication modules that were used from the \
1756N/A authentication service will be mapped to the <code>amr</code> values. If you do not require amr values, or are not \
1756N/Aa120.help=The attribute name of the modified timestamp in the identity repository (must also be added to the User \
1224N/Aa121.help=The attribute name of the created timestamp in the identity repository (must also be added to the User \