Denying a user access using custom claims - kmd-identity/documentation GitHub Wiki
Denying a user access using custom claims
KMD Identity supports using the custom claims feature to deny a user access to an application. If the custom claims endpoint returns a claim with type http://access.userforbidden, it indicates that the user must not be allowed to continue the authentication flow for the application. If the claim is present, any other claims returned by the endpoint are ignored. Note that it is only recommended to use this claim for applications that are unable to evaluate the issued token and perform their own authorization handling after authentication.
Only the claim type is evaluated by KMD Identity. The claim value is ignored and can contain any value.
Example: { "http://access.userforbidden": "AnyValue" }
Authentication flow
When KMD Identity receives the http://access.userforbidden claim from the custom claims endpoint, KMD Identity stops the authentication flow. Instead of issuing a token, KMD Identity redirects the user back to the application with a protocol-specific error response.
For SAML applications, a response with status Responder and sub-status RequestDenied is returned.
For OpenID applications, the error: access_denied is returned.
Recommendation
KMD Identity generally recommends that applications perform authorization checks themselves after receiving the issued token. Applications should evaluate the claims in the token and present a user-friendly message explaining why the user does not have access, including any relevant next steps. Use the http://access.userforbidden claim only when the application is unable to evaluate token contents or perform its own authorization handling.