Skip to main content

Additional Parameter Customization

The OAuth2 and OIDC specifications account for extensibility and customization on the part of implementors and consumers of these features. This includes arguments and parameters specific to a particular Authorization Server, or perhaps intermediary proxies and load balancers that need certain information to properly route requests.

Regardless of the reason behind these customizations, there are a number of places where developers wish to extend built-in functionality with their own custom arguments.

Parameter content types​

Since authentication flows typically perform requests/responses using either text/json or application/x-www-form-urlencoded encoding, the parameters supported for customization are represented as a simple [String: String] dictionary. This provides for the maximum compatibility as it can be used within both JSON and URLEncoded request bodies, or URI query string arguments.

Possible customization points​

Tracking state, and determining when and where certain arguments need to be supplied throughout an authentication workflow, can be challenging. To simplify development it's important that there isn't too much variability in how and when customizations can take place. Furthermore, dealing with mutations of objects at runtime can cause difficulties such as data race conditions, multithreading concurrent access problems, and so forth.

However, to ensure the best degree of flexibility, there are two primary places where a developer can supply the additionalParameters option:

  1. An Authorization Flow's constructor — This allows all requests made within an instance of a flow to share common arguments. This may be used to supply information to a server such as the intent of the flow, parameters used to control ingress / load balancer behavior, etc.
  2. Within the context for an authentication flow session — Customizes arguments used for a single authentication session. This could be used to supply additional state like a custom user identifier, an analytics tracking identifier, etc.