Configurable Error Mapper
Description
Defines how to respond based on configuration.
May be used by
Properties
Responses by Authentication Failure Type (
authenticationFailures) Description
Maps authentication failure types to HTTP error responses.
The authentication failure types can be defined by the authenticator. Known types seen in one-shot flow:
- "user not found"
- "user required"
- "user name ambiguous"
- "user locked"
- "user temporarily locked"
- "user invalid"
- "user not permitted at this time"
- "user not permitted at this client"
- "device blocked"
- "device busy with another authentication request"
- "unspecified"
- "password required"
- "password wrong"
- "password change required"
- "token required"
- "token wrong"
- "next token required"
- "binding token required"
- "token expired"
- "certificate required"
- "certificate does not match user"
- "certificate not yet valid"
- "certificate expired"
- "certificate revoked"
- "certificate issuer not trusted"
Attributes
Plugin-Map
Optional
Assignable plugins
Default Authentication Failure Response (
defaultAuthenticationFailure) Description
Specifies how to respond in case no specific authentication failure type matches.
Attributes
Plugin-Link
Optional
Assignable plugins
Authorization Failure Response (user has no access) (
userHasNoAccess) Description
Defines how to respond if the user has no access to the target application/service (authorization failure).
Attributes
Plugin-Link
Optional
Assignable plugins
Credential Extraction Failure Response (
credentialCannotBeExtracted) Description
Defines how to respond if the credential cannot be extracted from the request.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)
type: ConfigurableErrorMapperFactory
id: ConfigurableErrorMapperFactory-xxxxxx
displayName:
comment:
properties:
authenticationFailures:
credentialCannotBeExtracted:
defaultAuthenticationFailure:
userHasNoAccess: