Admin SSO Ticket Request Authentication
queryParameterName) ticketDecoder) The ticket decoder plugin used to decode the SSO ticket.
Security note: If tickets are transported via the web browser (in the URL), they need to be protected. Make sure to use an appropriate ticket decoder securing the ticket (e.g. digitally signed and/or encrypted)!
acceptedSsoTicketRepository) Configures the repository used to store accepted SSO tickets and reject previously accepted ones.
The in-memory repository cannot be used if multiple instances of IAM are deployed in parallel (failover, horizontal scaling). Furthermore, the in-memory repository does not preserve previously accepted SSO tickets across IAM restarts.
contextDataExtractors) usernameKey) providedUsernameKey) The ticket key containing the provided username, which is used for logging and possibly displayed.
This is not combinable with Username Transformation. If the ticket does not contain a provided username, the value from "Username Key" is used.
rolesKey) userStore) usernameTransformers) staticRoles) rolesBlocklist)
type: AdminSsoTicketRequestAuthentication
id: AdminSsoTicketRequestAuthentication-xxxxxx
displayName:
comment:
properties:
acceptedSsoTicketRepository:
contextDataExtractors:
providedUsernameKey:
queryParameterName:
rolesBlocklist:
rolesKey:
staticRoles:
ticketDecoder:
userStore:
usernameKey: username
usernameTransformers: