On Behalf Login Identity Propagation
This identity propagator performs a login 'on behalf' of the user at a backend web application. It performs the necessary login steps to obtain an authenticated session from login into the backend application. Then it attaches the session cookie to the user's authenticated session, thus enabling access to the backend application.
The login process is configured as a sequence of on behalf login steps. Each on behalf login step performs a HTTP operation and can store newly gathered information in an information storage for the next step.
For example: A first on behalf login step executes a HTTP GET request on the web application's login page and extracts the CSRF protection token. A next on behalf login step submits the login form with username, password and the extracted CSRF token.
On behalf logins are not robust against changes of the web application. Therefore, this identity propagation mechanism is only recommended for legacy application that do not accept another way of identity propagation.
httpClient) onBehalfLoginSteps) cookieMappings) forwardToLastRedirectLocation) Location header in the response of the last "On Behalf Login Step", under the conditions that
- a forward location is present in the last response from the backend and
- the forward location matches at least one regex in the "Allowed Forward Location" patterns.
allowedForwardLocations) This setting is only relevant if "Forward User To Last Redirect Location" is enabled. In that case the forward location must match at least one regex in order to be accepted. If the forward location does not match any regex, the default forward location is used.
- The forward location will always be an absolute URL, relative URLs are not supported.
- The forward location is from the on behalf HTTP clients perspective, which might be different from the users perspective, if Airlock IAM is behind an Airlock Gateway. This is because the Airlock Gateway may rewrite the forward location.
- URLs with any 'User Information' part in front of the host name (for example "https://user@domain.com/") are never accepted.
valueProviders) condition)
type: OnBehalfLoginIdentityPropagation
id: OnBehalfLoginIdentityPropagation-xxxxxx
displayName:
comment:
properties:
allowedForwardLocations: [^/.*]
condition:
cookieMappings:
forwardToLastRedirectLocation: false
httpClient:
onBehalfLoginSteps:
valueProviders: