Adminapp
startPages) users) - Authentication of users
- Management of user credentials and tokens
- Management of users
accessControl) maintenanceMessages) administrators) - Authentication of administrators
- Authorization of administrators
- Management of administrators (optional)
tokens) - Management of tokens
technicalClients) rest) gatewaySettings) If no settings are configured, extra information from the reverse proxy will not be available and it may be harder to correlate log messages that are written to different log files.
eventSettings) serviceContainerSharedSecret) logViewer) realmAdministration) Enables simple realm administration, where the rights of administrators are limited to a single realm. Administrators can only manage users that are in the same realm and newly created users are automatically assigned to the realm of the current administrator.
The assignment of a realm to an administrator requires super administrator authorization.Simple realm administration cannot be combined with realms mode, i.e. it must not be configured if the Adminapp uses the "Delegation-based Access Control" plugin.
sessionIdleTimeout) sessionLifetime) sameSitePolicy) Specifies the 'SameSite' cookie attribute of the IAM session cookie 'iam-session-id'. The 'Secure' attribute is automatically set based on whether the request was performed using http or https (see exception for 'None' below).
- Strict: The cookie is not sent in cross-origin requests.
- Lax: The cookie is sent in some cross-origin requests, such as GET requests.
- None: The cookie is sent in cross-origin requests. In this case, the 'Secure' Cookie-Attribute is always set, regardless of whether the request was performed using http or https.Use this setting when using SAML2 in combination with cross-domain POST Bindings.
- No SameSite Attribute: No attribute is set. Browsers apply their default behaviour, usually 'Lax'.
languageSettings) If not set, the default language is German and the allowed languages are German, English and French.
stateRepository) customLoginUrl) The page displayed instead of the default login page. This can be used if authentication is done by an external service.
This value must not be URL encoded. Only URLs starting with "https://" or "http://" are treated as absolute URLs, otherwise the redirect is relative. Furthermore, if the URL starts with "app/" or "/app/" the redirect is performed within the Adminapp UI (context path not needed).
This property can be overridden by the loginUrl URL parameter (see Allowed Login URL Pattern).
afterLogoutUrl) The forward page displayed after the logout if no location parameter is set.
This value must not be URL encoded. Only URLs starting with "https://" or "http://" are treated as absolute URLs, otherwise the redirect is relative. Furthermore, if the URL starts with "app/" or "/app/" the redirect is performed within the Adminapp UI (context path not needed).
This property can be overridden by the afterLogout URL parameter (see Allowed After Logout URL Pattern).
allowedLoginUrlPattern) A regular expression describing the Login URLs that are allowed to be sent to IAM in the loginUrl URL parameter.
A matching URL will be used to redirect users who have not yet authenticated or whose session has expired. If no pattern is configured, no URL will match. Matching URLs will have precedence over the URL configured in Custom Login URL.
allowedAfterLogoutUrlPattern) A regular expression describing the Logout URLs that are allowed to be sent to IAM in the afterLogoutUrl URL parameter.
A matching URL will be used to redirect the user after a successful logout in IAM. If no pattern is configured, no URL will match. Matching URLs will have precedence over the URL configured in After Logout URL.
skin) skinFromParamAllowed) instanceTag) contentSecurityPolicy) Neither the Config Editor nor the Service Container are covered by this CSP.
licenseAnalytics) Airlock IAM always collects and transmits license analytics data, as per our terms and conditions.
In this property, you may enable additional usage data collection to help improve Airlock IAM.
logUserTrailToDatabase) Configures the database settings to use when persisting user trail log entries.
If this value is defined, then all user trail log messages generated by the Adminapp module will additionally be forwarded to the database configured within the referenced repository plugin.
All forwarded log entries are stored inside the table "USER_TRAIL_LOG". Note that setting this value does not disable writing log messages to the Adminapp log file.
correlationIdSettings) Defines settings for correlation ID transfer and logging inside the Adminapp module.
If undefined, no correlation ID will be logged for this module.
customExtensions)
type: Adminapp
id: Adminapp-xxxxxx
displayName:
comment:
properties:
accessControl:
administrators:
afterLogoutUrl: app/login
allowedAfterLogoutUrlPattern:
allowedLoginUrlPattern:
contentSecurityPolicy:
correlationIdSettings:
customExtensions:
customLoginUrl:
eventSettings:
gatewaySettings:
instanceTag:
languageSettings:
licenseAnalytics:
logUserTrailToDatabase:
logViewer:
maintenanceMessages:
realmAdministration:
rest:
sameSitePolicy: LAX
serviceContainerSharedSecret:
sessionIdleTimeout: 30m
sessionLifetime: 8h
skin: blue
skinFromParamAllowed: false
startPages: [viewLog, listUsers, manageTokens]
stateRepository:
technicalClients:
tokens:
users: