← Back to plugin index

Cookie Ticket Adder

Description
Adds a ticket string as a response cookie.
Type name
CookieTicketAdder
Class
com.airlock.iam.authentication.application.configuration.idpropagation.CookieTicketAdderConfig
May be used by
Properties
Cookie Name (cookieName)
Description

The name of the cookie used to transport the ticket.

Only one cookie per cookie path and name can exist, therefore the name of this cookie must be distinct from all other cookie names used by this applications (such as "JSESSIONID").

Attributes
String
Mandatory
Example
AUTH_TICKET
Cookie Path (cookiePath)
Description

The path for which the cookie is set. This determines with which future requests the cookie will be sent to the server.

To add the cookie to all requests to a given domain, the value "/" can be used. If the cookie should be limited to a certain backend, the corresponding context path should be used.

Only one cookie per cookie path and name can exist, therefore the name of this cookie must be distinct from all other cookie for the same path (such as "JSESSIONID").

When using an Airlock Gateway (WAF), the Gateway configuration flag Interpret Cookie Domains must be set. Otherwise the cookie path is ignored and cookies in the cookie store are sent with back-end HTTP requests of the same session.

Attributes
String
Optional
Default value
/
Example
/
Example
/appl1
Example
/appl2
Cookie Domain (cookieDomain)
Description
The domain for which the cookie is set. This determines with which future requests the cookie will be sent to the server.

Because of security restrictions in browsers (same origin policy) it is usually not possible to set a cookie for a different domain (except subdomains).

Airlock Gateway (WAF) handle cookies differently and allow setting cookies for other domains within the protected infrastructure while not exposing them to the internet. The Gateway configuration flag Interpret Cookie Domains needs to be enabled for this feature. If this flag is enabled, also the following special domain names are supported:

  • An empty value results in the cookie only being sent to the origin server that set the cookie.
  • The value .* results in cookies being sent to all back-end servers.
  • Setting a different hostname results in the cookie being sent to the back-end host with that hostname.
Consult the Airlock Gataway documentation for more information on cookie handling.

Attributes
String
Optional
Example
.*
Example
@www.test.com
Example
ergon.ch
Secure Flag (secureFlag)
Description
If enabled, the "secure"-flag of the cookie is set.

If the cookie is marked as secure, the browser (and any HTTP proxy behaving like a browser) should send the cookie only over secure connections.

Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)

type: CookieTicketAdder
id: CookieTicketAdder-xxxxxx
displayName: 
comment: 
properties:
  cookieDomain:
  cookieName:
  cookiePath: /
  secureFlag: true