← Back to plugin index

Legacy ID Propagation Adapter

Description

Adapter for a legacy Identity Propagator plugin.

The set of identity propagators that can be configured is limited to those that don't redirect the response and don't require the HTTP request.

The roles made available to the identity propagator are those obtained by the Role Provider plugins configured here. Thus, if no Role Providers are configured, the identity propagator will not get any roles, not even the user's roles from the DB.

Type name
LegacyIdPropagator
Class
com.airlock.iam.authentication.application.configuration.idpropagation.LegacyIdPropagatorConfig
May be used by
Properties
Condition (condition)
Description
Defines the condition under which the users identity is propagated using the configured identity propagation.
Attributes
Plugin-Link
Optional
Assignable plugins
Role Providers (roleProviders)
Description
Plugins to determine the roles to propagate. These are only application-specific roles, not the Airlock Gateway (WAF) roles. If nothing is configured, no roles can be propagated.
Attributes
Plugin-List
Optional
Assignable plugins
Username Providers (usernameProviders)
Description
Plugins to determine an alternative username to propagate. This username is used as user ID for this identity propagation. The providers are asked to provide an alternative username in configured order. After the first username is supplied, subsequent providers are no longer invoked. If nothing configured, or no provider supplies a username, the user ID of the authenticated user is propagated.

Note that when possible these transformations should be configured in the target application instead. However, if username transformations are configured both here and in the target application, then the transformations defined in the target application will be ignored and the transformations defined here will be applied directly to the technical user ID.

Attributes
Plugin-List
Optional
License-Tags
SubIdentities
Assignable plugins
Context-Data Providers (contextDataProviders)
Description
Values provided by these value map providers are added to the persistent context-data of the authentee that is created for the identity propagator. They can then be referred to like normal context-data. Providers may overwrite each others values. The order of the list defines the runtime order and therefore influence the resulting data set.
Attributes
Plugin-List
Optional
Assignable plugins
Password Attribute Key (passwordAttributeKey)
Description

The optional key by which the password should be retrieved from password steps.

If no key is configured or no password was entered for this key, no password is propagated.

Attributes
String
Optional
Suggested values
PASSWORD
YAML Template (with default values)

type: LegacyIdPropagator
id: LegacyIdPropagator-xxxxxx
displayName: 
comment: 
properties:
  condition:
  contextDataProviders:
  identityPropagator:
  passwordAttributeKey:
  roleProviders:
  usernameProviders: