← Back to plugin index

HTTP Header Token Extractor (as SSO Credential)

Description

Extracts a token from an HTTP header, decodes it using the specified ticket decoder (e.g. JWT) and provides a "Single-Sign-On-Credential" to the authenticator.
This extractor can be used to verify JWTs in "Authorization" headers (to remove the "Bearer "-Prefix from the header value use "Header Value Conversion Pattern" and "Header Value Conversion Replacement").

This extractor can only be used with authenticators that are able to process Single-Sign-On-Credentials (e.g. the "SSO Credential Authenticator").

Type name
HttpHeaderTokenExtractor
Class
com.airlock.iam.authentication.application.configuration.oneshot.HttpHeaderTokenExtractorConfig
May be used by
Properties
Header Name (headerName)
Description
The name of the header.
Attributes
String
Mandatory
Example
Authorization
URL Encoding Scheme (urlEncodingScheme)
Description
The encoding of the URL encoding.
Attributes
String
Optional
Default value
UTF-8
Allowed values
UTF-8, ISO-8859-1, UTF-16, UTF-16BE, UTF-16LE, US-ASCII
Decoder (decoder)
Description
The ticket decoder to decode the value of the HTTP header.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Username Key (usernameKey)
Description
The name (key) under which the extracted username is stored in the ticket (and therefore the "SSO Credential")
Attributes
String
Optional
Default value
username
Roles Key (rolesKey)
Description
The ticket key under which the extracted roles are stored in the ticket (and therefore the "SSO Credential")
Attributes
String
Optional
Default value
roles
Context Properties (contextProperties)
Description
The keys in the ticket that are used as attributes in the credential under the same key name. These are later used as context-data fields. Note that the key must have only one value attached (not like roles that has multiple values). Moreover, in case there is no entry for the given key, the corresponding attribute value is set to null.
Attributes
String-List
Optional
Header Value Conversion Pattern (headerValueConversionPattern)
Description

Regular expression pattern containing a group (a section in parentheses) that can be used in conjunction with property "Header Value Conversion Replacement" in order to transform the header value before it is decoded. If the header value does not match the pattern at all, no transformation is performed.

Example: The pattern "^Bearer (.*)$" and the replacement pattern "$1" will transform the header value "Bearer ABCD1234" to "ABCD1234" before it is decoded.

Attributes
RegEx
Optional
Header Value Conversion Replacement (headerValueConversionReplacement)
Description
The replacement string used in conjunction with property "Header Value Conversion Pattern" in order to transform the header value. The token "$1" is used to reference the string matching the group in the pattern. See property "Header Value Conversion Pattern" for examples.
Attributes
String
Optional
Example
$1
YAML Template (with default values)

type: HttpHeaderTokenExtractor
id: HttpHeaderTokenExtractor-xxxxxx
displayName: 
comment: 
properties:
  contextProperties:
  decoder:
  headerName:
  headerValueConversionPattern:
  headerValueConversionReplacement:
  rolesKey: roles
  urlEncodingScheme: UTF-8
  usernameKey: username