You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何限制敏感数据仅对资源服务器开放?[OAuth2/OpenID]

How to Restrict Client Access to Sensitive /userinfo Data (e.g., contract_ID) While Allowing Resource Server Access

Great question! This is a common security requirement in OAuth2/OpenID Connect setups—you want to keep sensitive user data out of client hands but let your trusted resource servers access it to perform necessary operations. Here’s how to implement this effectively:

1. Scope-Based Access Control (Core Solution)

Scopes are the foundation of OAuth2 authorization, and you can use them to gate access to sensitive fields in the /userinfo endpoint:

  • Limit client scopes: Only grant your client non-sensitive scopes like openid or email—never include a scope that allows access to contract_ID (e.g., avoid contract:read for clients).
  • Restrict sensitive data to resource server scopes: Create a dedicated scope (e.g., internal:contract_access) that’s only assigned to your resource server. Configure your identity provider (IDP) to return contract_ID in /userinfo responses only when the access token includes this restricted scope.
  • Validate scopes at the IDP: Ensure the /userinfo endpoint checks the token’s scopes before returning sensitive fields. Clients without the internal:contract_access scope will never see contract_ID, even if they call /userinfo directly.

2. Token Introspection for Resource Servers

If your IDP supports token introspection, this is a robust way for your resource server to fetch full user data without exposing it to clients:

  • Your resource server sends the client’s access token to the IDP’s introspection endpoint (along with its own client credentials for authentication).
  • The IDP returns a detailed response including the user’s full profile (including contract_ID) if the token is valid and the resource server is authorized to access this data.
  • Clients can’t use this endpoint because they don’t have the resource server’s credentials, so they can’t retrieve sensitive info this way.

3. Restrict /userinfo Endpoint Access by Caller

You can configure your IDP to only return sensitive fields when the request comes from your trusted resource server:

  • Authenticate the resource server: When your resource server calls /userinfo, have it send its own client ID and secret (via HTTP Basic auth or a client assertion) alongside the user’s access token.
  • Filter responses by caller: The IDP checks both the user’s access token and the caller’s identity. If the caller is your resource server, return the full user data; if it’s a client, return only non-sensitive fields.
  • Optional: IP whitelisting: For extra security, restrict /userinfo access to your resource server’s IP range when sensitive data is requested.

4. Separate ID Tokens vs. Access Tokens

OpenID Connect differentiates between ID tokens (for client-side identity verification) and access tokens (for resource access):

  • ID tokens for clients: Configure your IDP to exclude contract_ID from ID tokens. Clients will only get basic identity info (like sub, email) in the ID token, which they can use for authentication without seeing sensitive data.
  • Access tokens for resource servers: The resource server uses the access token to call /userinfo or introspection endpoints, where it can retrieve the full user profile including contract_ID.

Key Security Notes

  • Always use HTTPS for all token and /userinfo requests to prevent token interception.
  • Rotate resource server credentials regularly to minimize risk if they’re compromised.
  • Audit your IDP’s scope assignments periodically to ensure clients never get access to sensitive scopes by mistake.

内容的提问来源于stack exchange,提问作者Thibaut FAURE

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 09:52:17