← Back to plugin index

Admin SSO Ticket Request Authentication

Description
Extracts an SSO ticket from a request to authenticate the current session.
Type name
AdminSsoTicketRequestAuthentication
Class
com.airlock.iam.admin.application.configuration.credential.AdminSsoTicketRequestAuthenticationConfig
May be used by
Properties
Query Parameter Name (queryParameterName)
Description
The name of the query parameter bearing the SSO ticket to be extracted.
Attributes
String
Mandatory
Example
sso
Ticket Decoder (ticketDecoder)
Description

The ticket decoder plugin used to decode the SSO ticket.

Security note: If tickets are transported via the web browser (in the URL), they need to be protected. Make sure to use an appropriate ticket decoder securing the ticket (e.g. digitally signed and/or encrypted)!

Attributes
Plugin-Link
Mandatory
Assignable plugins
Accepted SSO Tickets Repository (acceptedSsoTicketRepository)
Description

Configures the repository used to store accepted SSO tickets and reject previously accepted ones.

The in-memory repository cannot be used if multiple instances of IAM are deployed in parallel (failover, horizontal scaling). Furthermore, the in-memory repository does not preserve previously accepted SSO tickets across IAM restarts.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Context Data Extractors (contextDataExtractors)
Description
List of ticket context data extractors that extract custom data from the ticket.
Attributes
Plugin-List
Optional
Assignable plugins
Username Key (usernameKey)
Description
The ticket key containing the username.
Attributes
String
Optional
Default value
username
Provided Username Key (providedUsernameKey)
Description

The ticket key containing the provided username, which is used for logging and possibly displayed.

This is not combinable with Username Transformation. If the ticket does not contain a provided username, the value from "Username Key" is used.

Attributes
String
Optional
Roles Key (rolesKey)
Description
The ticket key containing the user's roles. If not configured, no roles are extracted from the ticket.
Attributes
String
Optional
Example
roles
User Store (userStore)
Description
If configured, the user is loaded from local persistence and checked for validity. Authentication fails if the user is not found or is invalid. If no user store is configured, no persistency look-up takes place and the authentication is performed on data contained within the credential only.
Attributes
Plugin-Link
Optional
Assignable plugins
Username Transformation (usernameTransformers)
Description
Transforms the provided username from the credential to a technical user ID.
Attributes
Plugin-List
Optional
Assignable plugins
Static Roles (staticRoles)
Description
Static list of roles granted to the authenticated user.
Attributes
String-List
Optional
Roles Blocklist (rolesBlocklist)
Description
List of role names that won't be granted to the authenticated user. The block list is also applied to persistent roles (if available).
Attributes
String-List
Optional
YAML Template (with default values)

type: AdminSsoTicketRequestAuthentication
id: AdminSsoTicketRequestAuthentication-xxxxxx
displayName: 
comment: 
properties:
  acceptedSsoTicketRepository:
  contextDataExtractors:
  providedUsernameKey:
  queryParameterName:
  rolesBlocklist:
  rolesKey:
  staticRoles:
  ticketDecoder:
  userStore:
  usernameKey: username
  usernameTransformers: