← Back to plugin index

Adminapp

Description
Configures the Adminapp module used to administrate users, credentials, and messages.
Type name
Adminapp
Class
com.airlock.iam.admin.application.configuration.Adminapp
Properties
Start Pages (startPages)
Description
The admin application page to be displayed after login. If more than one start page is configured, the system displays the first page for which the current user is authorized. If none is found, the system displays an empty page.
Attributes
String-List
Optional
Default value
[viewLog, listUsers, manageTokens]
Users (users)
Description
Defines settings related to users. This includes
  • Authentication of users
  • Management of user credentials and tokens
  • Management of users
If not provided, the users management is disabled.
Attributes
Plugin-Link
Optional
Assignable plugins
Access Control (accessControl)
Description
Defines access control in the Adminapp and to the Adminapp REST API.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Maintenance Messages (maintenanceMessages)
Description
Configures the maintenance message facility of the Adminapp.
Attributes
Plugin-Link
Optional
Assignable plugins
Administrators (administrators)
Description
Defines settings related to administrators. This includes
  • Authentication of administrators
  • Authorization of administrators
  • Management of administrators (optional)
Attributes
Plugin-Link
Mandatory
Assignable plugins
Tokens (tokens)
Description
Defines settings related to tokens. This includes
  • Management of tokens
Attributes
Plugin-Link
Optional
Assignable plugins
Technical Clients (technicalClients)
Description
Defines settings related to technical clients.
Attributes
Plugin-Link
Optional
License-Tags
TechClients
Assignable plugins
REST API Configuration (rest)
Description
Enables REST services for the Adminapp.
Attributes
Plugin-Link
Optional
Assignable plugins
Gateway Settings (gatewaySettings)
Description
Settings regarding an Airlock Gateway or Airlock Microgateway reverse proxy placed in front of Airlock IAM.

If no settings are configured, extra information from the reverse proxy will not be available and it may be harder to correlate log messages that are written to different log files.

Attributes
Plugin-Link
Optional
Assignable plugins
Event Settings (eventSettings)
Description
Configures handling of events in the Adminapp.
Attributes
Plugin-Link
Optional
Assignable plugins
Service Container Shared Secret (serviceContainerSharedSecret)
Description
The service container secret is used to access the service container from the Adminapp. The shared secret will be used to encrypt the SSO ticket, sent from the Adminapp to the service container in order to authenticate the admin. The shared secret must be identical to the property Service Container Shared Secret within Service Container (Advanced Settings). When not configured, no Service Container link will be displayed in Adminapp.
Attributes
String
Optional
Sensitive
Log Viewer (logViewer)
Description
Configuration of the Log Viewer.
Attributes
Plugin-Link
Optional
Assignable plugins
Simple Realm Administration (realmAdministration)
Description

Enables simple realm administration, where the rights of administrators are limited to a single realm. Administrators can only manage users that are in the same realm and newly created users are automatically assigned to the realm of the current administrator.

The assignment of a realm to an administrator requires super administrator authorization.

Simple realm administration cannot be combined with realms mode, i.e. it must not be configured if the Adminapp uses the "Delegation-based Access Control" plugin.

Attributes
Plugin-Link
Optional
License-Tags
RealmAdministration
Assignable plugins
Session Idle Timeout (sessionIdleTimeout)
Description
Session idle timeout for the Adminapp (including Config Editor). When IAM is deployed behind an Airlock Gateway (WAF), timeout and lifetime values should always be longer than those maintained by the Gateway.
Attributes
String
Optional
Default value
30m
Example
30m
Example
2h 15m
Session Lifetime (sessionLifetime)
Description
Session lifetime for the Adminapp (but not for the Config Editor). Unlike an idle timeout, the lifetime cannot be extended by activity and is always terminated once the lifetime has been reached. When IAM is deployed behind an Airlock Gateway (WAF), timeout and lifetime values should always be longer than those maintained by the Gateway.
Attributes
String
Optional
Default value
8h
Example
4h 30m
Example
8h
Session Cookie SameSite Policy (sameSitePolicy)
Description

Specifies the 'SameSite' cookie attribute of the IAM session cookie 'iam-session-id'. The 'Secure' attribute is automatically set based on whether the request was performed using http or https (see exception for 'None' below).

  • Strict: The cookie is not sent in cross-origin requests.
  • Lax: The cookie is sent in some cross-origin requests, such as GET requests.
  • None: The cookie is sent in cross-origin requests. In this case, the 'Secure' Cookie-Attribute is always set, regardless of whether the request was performed using http or https.Use this setting when using SAML2 in combination with cross-domain POST Bindings.
  • No SameSite Attribute: No attribute is set. Browsers apply their default behaviour, usually 'Lax'.
Attributes
Enum
Optional
Default value
LAX
Language Settings (languageSettings)
Description
Configures language settings.
If not set, the default language is German and the allowed languages are German, English and French.
Attributes
Plugin-Link
Optional
Assignable plugins
State Repository (stateRepository)
Description
Defines where IAM stores all state. As long as only one instance of IAM is running (no horizontal scaling), the in-memory repository can be used.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Custom Login URL (customLoginUrl)
Description

The page displayed instead of the default login page. This can be used if authentication is done by an external service.

This value must not be URL encoded. Only URLs starting with "https://" or "http://" are treated as absolute URLs, otherwise the redirect is relative. Furthermore, if the URL starts with "app/" or "/app/" the redirect is performed within the Adminapp UI (context path not needed).

This property can be overridden by the loginUrl URL parameter (see Allowed Login URL Pattern).

Attributes
String
Optional
Example
https://another.server.com/login
Example
app/login
Example
/mycustomresource/login
After Logout URL (afterLogoutUrl)
Description

The forward page displayed after the logout if no location parameter is set.

This value must not be URL encoded. Only URLs starting with "https://" or "http://" are treated as absolute URLs, otherwise the redirect is relative. Furthermore, if the URL starts with "app/" or "/app/" the redirect is performed within the Adminapp UI (context path not needed).

This property can be overridden by the afterLogout URL parameter (see Allowed After Logout URL Pattern).

Attributes
String
Optional
Default value
app/login
Example
https://another.server.com/logout-disclaimer
Example
app/login
Example
/mycustomresource/logout-disclaimer
Allowed Login URL Pattern (allowedLoginUrlPattern)
Description

A regular expression describing the Login URLs that are allowed to be sent to IAM in the loginUrl URL parameter.

A matching URL will be used to redirect users who have not yet authenticated or whose session has expired. If no pattern is configured, no URL will match. Matching URLs will have precedence over the URL configured in Custom Login URL.

Attributes
RegEx
Optional
Allowed After Logout URL Pattern (allowedAfterLogoutUrlPattern)
Description

A regular expression describing the Logout URLs that are allowed to be sent to IAM in the afterLogoutUrl URL parameter.

A matching URL will be used to redirect the user after a successful logout in IAM. If no pattern is configured, no URL will match. Matching URLs will have precedence over the URL configured in After Logout URL.

Attributes
RegEx
Optional
Skin Color (skin)
Description
The skin of the Adminapp. This configuration may be overridden by the skin URL parameter, if the property "Allow Skin URI Parameter" is enabled.
Attributes
String
Optional
Default value
blue
Allowed values
blue, green, red, orange, violet, purple, grey, black
Allow Skin URL Parameter (skinFromParamAllowed)
Description
Enables overriding the Adminapp skin with the skin URL parameter.
Attributes
Boolean
Optional
Default value
false
Custom Instance Tag (instanceTag)
Description
Labels the instance with a custom tag that is displayed in the Adminapp. This can be used in combination with the 'Skin Color' property to visually identify an instance.
Attributes
String
Optional
Content Security Policy (CSP) (contentSecurityPolicy)
Description
Content Security Policy (CSP) for the Adminapp.

Neither the Config Editor nor the Service Container are covered by this CSP.

Attributes
Plugin-Link
Optional
Assignable plugins
License and Usage Analytics (licenseAnalytics)
Description

Airlock IAM always collects and transmits license analytics data, as per our terms and conditions.

In this property, you may enable additional usage data collection to help improve Airlock IAM.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Log User Trail To Database (logUserTrailToDatabase)
Description

Configures the database settings to use when persisting user trail log entries.

If this value is defined, then all user trail log messages generated by the Adminapp module will additionally be forwarded to the database configured within the referenced repository plugin.

All forwarded log entries are stored inside the table "USER_TRAIL_LOG". Note that setting this value does not disable writing log messages to the Adminapp log file.

Attributes
Plugin-Link
Optional
Assignable plugins
Correlation ID Settings (correlationIdSettings)
Description

Defines settings for correlation ID transfer and logging inside the Adminapp module.

If undefined, no correlation ID will be logged for this module.

Attributes
Plugin-Link
Optional
Assignable plugins
Custom Extensions (customExtensions)
Description
Custom extensions for the Adminapp.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: Adminapp
id: Adminapp-xxxxxx
displayName: 
comment: 
properties:
  accessControl:
  administrators:
  afterLogoutUrl: app/login
  allowedAfterLogoutUrlPattern:
  allowedLoginUrlPattern:
  contentSecurityPolicy:
  correlationIdSettings:
  customExtensions:
  customLoginUrl:
  eventSettings:
  gatewaySettings:
  instanceTag:
  languageSettings:
  licenseAnalytics:
  logUserTrailToDatabase:
  logViewer:
  maintenanceMessages:
  realmAdministration:
  rest:
  sameSitePolicy: LAX
  serviceContainerSharedSecret:
  sessionIdleTimeout: 30m
  sessionLifetime: 8h
  skin: blue
  skinFromParamAllowed: false
  startPages: [viewLog, listUsers, manageTokens]
  stateRepository:
  technicalClients:
  tokens:
  users: