Add an OAuth Groovy script rule to determine whether to grant access to a target site based on the results returned from a Groovy script that evaluates request details and OAuth details.
Since the regular Groovy rule and the OAuth Groovy rule differ in the scope of their functionality, the relevant rules are tagged for Web App or for API, respectively, in the rules list.
- Click Access and then go to .
- Click + Add Rule.
In the Name field, enter a unique name, up to 64
Special characters and spaces are allowed.
- From the Type list, select OAuth Groovy Script (for API).
In the Groovy Script field, enter the Groovy script to
use for rule evaluation.
To create an OAuth scope rule that matches more than one scope, you might include the
hasScopes("access","portfolio")matcher in your Groovy script.Note:
Groovy script rules must end execution with a matcher instance. For more information, see Matcher usage reference.
To configure rejection handling, click Show Advanced
Settings, then select a rejection handling method.
- If you select Default, use the Rejection Handler list to select an existing rejection handler that defines whether to display an error template or redirect to a URL.
- If you select Basic, you can customize an error
message to display as part of the default error page rendered in the end user's
browser if rule evaluation fails. This page is among the templates you can
modify with your own branding or other information. If you select
Basic, provide the following:
- In the Error Response Code field, enter the HTTP
status response code to send if rule evaluation fails.
The default is 403.
- In the Error Response Status Message field, enter
the HTTP status response message to send if rule evaluation fails.
The default is Forbidden.
- In the Error Response Template File field, enter the HTML template page for customizing the error message that displays if rule evaluation fails. This template file is located in the <PA_HOME>/conf/template/ directory.
- From the Error Response Content Type list, select
the type of content for the error response.
This lets the client properly display the response.
- In the Error Response Code field, enter the HTTP status response code to send if rule evaluation fails.
- Click Save.