← Back to plugin index

On Behalf Login Identity Propagation

Description

This identity propagator performs a login 'on behalf' of the user at a backend web application. It performs the necessary login steps to obtain an authenticated session from login into the backend application. Then it attaches the session cookie to the user's authenticated session, thus enabling access to the backend application.

The login process is configured as a sequence of on behalf login steps. Each on behalf login step performs a HTTP operation and can store newly gathered information in an information storage for the next step.

For example: A first on behalf login step executes a HTTP GET request on the web application's login page and extracts the CSRF protection token. A next on behalf login step submits the login form with username, password and the extracted CSRF token.

On behalf logins are not robust against changes of the web application. Therefore, this identity propagation mechanism is only recommended for legacy application that do not accept another way of identity propagation.

Type name
OnBehalfLoginIdentityPropagation
Class
com.airlock.iam.authentication.application.configuration.idpropagation.OnBehalfLoginIdentityPropagationConfig
May be used by
Properties
HTTP Client (httpClient)
Description
The HTTP client that connects to the web application.
Attributes
Plugin-Link
Mandatory
Assignable plugins
On Behalf Login Steps (onBehalfLoginSteps)
Description
Sequence of on behalf login steps that are performed to simulate the user's login process.
Attributes
Plugin-List
Mandatory
Assignable plugins
Cookie Mappings (cookieMappings)
Description
A list of cookies that are expected from the backend application and that are kept for subsequent access to this backend. Usually the only cookie to configure is the session cookie.
Attributes
Plugin-List
Mandatory
Assignable plugins
Forward To Last Redirect Location (forwardToLastRedirectLocation)
Description
If enabled, the client will be redirected to the URL specified in the Location header in the response of the last "On Behalf Login Step", under the conditions that
  1. a forward location is present in the last response from the backend and
  2. the forward location matches at least one regex in the "Allowed Forward Location" patterns.
Attributes
Boolean
Optional
Default value
false
Allowed Forward Locations (allowedForwardLocations)
Description
A list of regular expressions defining the allowed forward locations in the response of the last "On Behalf Login Step".
This setting is only relevant if "Forward User To Last Redirect Location" is enabled. In that case the forward location must match at least one regex in order to be accepted. If the forward location does not match any regex, the default forward location is used.
  • The forward location will always be an absolute URL, relative URLs are not supported.
  • The forward location is from the on behalf HTTP clients perspective, which might be different from the users perspective, if Airlock IAM is behind an Airlock Gateway. This is because the Airlock Gateway may rewrite the forward location.
  • URLs with any 'User Information' part in front of the host name (for example "https://user@domain.com/") are never accepted.
Attributes
RegEx-List
Optional
Default value
[^/.*]
Condition (condition)
Description
Defines the condition under which this identity propagation is executed.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: OnBehalfLoginIdentityPropagation
id: OnBehalfLoginIdentityPropagation-xxxxxx
displayName: 
comment: 
properties:
  allowedForwardLocations: [^/.*]
  condition:
  cookieMappings:
  forwardToLastRedirectLocation: false
  httpClient:
  onBehalfLoginSteps:
  valueProviders: