Gateway Session Terminator Subscriber (Adminapp)
Description
This event subscriber terminates a user's Airlock Gateway sessions. Upon an event trigger, the plugin contacts one or more Airlock Gateways via their REST APIs, terminating all sessions of the affected user. In clustered gateway deployments, it is sufficient to contact a single gateway node to invalidate the user’s sessions across the cluster.
For consistency, consider subscribing to the same events used by the 'Gateway Session Terminator Subscriber (Loginapp)'.
Prerequisites:
- The Gateway Audit Token in the Loginapp must be configured to contain only the username
- IAM must be able to open HTTP(S) connections to the Airlock Gateways. This may require changes to your network topology.
Security Advisory: Certain events can be triggered without an authenticated user session. Under Denial-of-Service conditions, such events may result in unintended session terminations and should therefore be selected with caution.
May be used by
Properties
Gateway REST APIs (
gatewayRestApiConnections) Description
The Airlock Gateway REST APIs that are invoked to terminate the user's sessions.
Attributes
Plugin-List
Mandatory
Assignable plugins
Event (
event) Description
The user event about which the subscriber should be notified.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Airlock 2FA Device Deleted Authentication Method Changed Context Data Changed Cronto Device Deleted Cronto Letter Ordered Device Token Deleted Email Address Added Email Address Changed Email Address Deleted FIDO Credential Deleted MTAN Token Deleted MTAN Token Phone Number Changed MTAN Token Registered Password Changed Password Letter Ordered User Created User Deleted User Locked User Realm Changed User Roles Changed User Unlocked
YAML Template (with default values)
type: AdminappGatewaySessionTerminatorEventSubscriber
id: AdminappGatewaySessionTerminatorEventSubscriber-xxxxxx
displayName:
comment:
properties:
event:
gatewayRestApiConnections: