← Back to plugin index

One-Shot Authentication Settings

Description

Configures the end-point used to authenticated HTTP requests with the Airlock Gateway (WAF)'s one-shot flow. It can be used, for example, to authenticate stateless REST calls.

The HTTP header of non-authenticated request are sent to this IAM end-point by the Airlock Gateway.
Make sure to use ".../login-oneshot/" as denied access URL on the corresponding gateway mappings.

This end-point may roughly do the following with the requests:

  • Extract a credential from the HTTP header (e.g. a bearer token or a cookie).
  • Call an Authenticator plugin with the credential (e.g. verify the bearer token).
  • Authenticate the request on the Airlock Gateway and append ID propagation information for the target application/service.
  • Respond as expected by the HTTP client in all cases(e.g. use expected HTTP response code).

All settings are configured in the list of target applications/services (see properties).
The target application/service is selected by the original request by the HTTP client (provided to IAM in various environment cookies).
In case no target application/service matches, the default target application/service is used.

Type name
OneShotAuthentication
Class
com.airlock.iam.authentication.application.configuration.oneshot.OneShotAuthenticationConfig
May be used by
Properties
Default Target Application/Service (defaultTargetApplication)
Description
The default target application/service to use in case no other target application/service matches. Note that the "URL Pattern" property is irrelevant for this target application/service.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Target Application/Service (targetApplications)
Description

List of target applications/services:

One of the target applications/services is selected by matching the "URL Pattern" against URL of the original HTTP request sent by the client (provided to IAM by several environment cookies).

They are matched in the order they are declared and the first matching is used. In case no one matches, the default target application/service is used.

Attributes
Plugin-List
Optional
Assignable plugins
User-specific Role-Timeouts (userSpecificRoleTimeouts)
Description
Configuration of user-specific idle-timeout and role life-time values per role.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: OneShotAuthentication
id: OneShotAuthentication-xxxxxx
displayName: 
comment: 
properties:
  defaultTargetApplication:
  targetApplications:
  userSpecificRoleTimeouts: