← Back to plugin index

Authenticator-based One-Shot Target Application

Description

Defines how to authenticate HTTP requests based on the original HTTP request sent by the client (provided to IAM in various Airlock Gateway environment cookies).

The following actions are applied for each request:

  1. Credential Extraction: Extract credential from the HTTP request (e.g. a bearer token or a cookie).
  2. Authentication: Call specified authenticator with credential (e.g. verify JWT ticket).
  3. Error handling: If authentication failes, the specified error mapper defines how to respond (e.g. send 401 to client).
  4. Authorization: Assure roles required to access application/services are given after authentication.
  5. ID-Propagation: provide information about authenticated user to target application/service.
  6. Set Airlock Gateway (WAF) roles: provide credentials/roles to Airlock Gateway to allow request to pass to target application/service.

Type name
AuthenticatorBasedOneShotTargetApplication
Class
com.airlock.iam.authentication.application.configuration.oneshot.OneShotTargetApplicationConfig
May be used by
Properties
Credential Extractor (credentialExtractorFactory)
Description
Extracts credential (e.g. basic auth, bearer token, cookie) from the request received from the Airlock Gateway (one-shot flow). The credential serves as input for the authenticator.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Authenticator (authenticator)
Description

Validates the credential from the credential extractor in order to authenticate the HTTP request.

Note:

  • Only non-interactive authentication steps (there is no way to interact with the HTTP client at this point - use the REST authentication API to do so if desired) may be configured.
  • The authenticator must know how to handle the credential type provided by the credential extractor.

A common use-case is to verify JWT tokens issued by an upfront authentication process (as "Authorization Bearer" header):

  • Extract bearer token from HTTP header (using the "HTTP Header Token Extractor (as SSO Credential)").
  • Authenticate the request using the "Lookup and Accept Authenticator" or the "SSO Credential Authenticator".

Attributes
Plugin-Link
Mandatory
Assignable plugins
Failure Responses (failureResponses)
Description
Defines how to respond if authentication fails (for wrong credentials and other errors).
Attributes
Plugin-Link
Optional
Assignable plugins
Enable User Trail Log (enableUserTrailLog)
Description

If enabled, a message is logged to the user trail log for every successful or unsuccessful authentication.

Caution: If the Airlock Gateway (WAF) is used in stateless mode, every single request may have to be authenticated by IAM due to missing roles. Hence, every request may generate a message in the user trail log depending on the Airlock Gateway configuration.

Attributes
Boolean
Optional
Default value
true
URL Pattern (urlPattern)
Description
The URL pattern (regular expression pattern) to identify this target application.

The first pattern (in the list of target applications) that matches the forward URL is used.
The matching is case-insensitive.

The URL pattern is ignored for the default target application.

Attributes
RegEx
Mandatory
Use Different Username (useDifferentUsername)
Description
If a user can have a different username at this target application, it can be specified here how the other username should be obtained. The following options are possible:
  • The name of the context data field in which this username is stored. Note that this field needs to be made persistent via the User Persister.
  • A fixed username (which is the same for all users). This should start with FIXED: followed by the username. E.g.: if the username is "admin", set this to "FIXED:admin".
  • Leave this empty, if no username is required or the standard username should be used.

The resulting username can be transformed further by using the Username Transformation property.

Attributes
String
Optional
License-Tags
SubIdentities
Example
applA_username
Example
email
Example
FIXED:admin
Username Transformation (usernameTransformation)
Description
List of transformation plugins which allow various mutations of the username. The transformations are applied in order. Note that some username transformer stop the transformation chain after successful application.

These transformations are applied after the "Use Different Username" property.

Attributes
Plugin-List
Optional
Assignable plugins
Use Different Password (useDifferentPassword)
Description
If a user needs a password for this target application, it can be specified here how it should be obtained. This is not supported by all plugins though. The following options are possible:
  • If no password is required for this application: leave empty.
  • If the user has (or can have) a different password at this application: The name of the context data field in which this password is to be stored. Remember that this field needs to be made persistent via the User Persister.
  • If a fixed password is used that is the same for all users: Prefix with FIXED: followed by the password, e.g. "FIXED:123456".
  • If the user's main password (i.e. the password used to login to Airlock IAM) is used: Leave the field empty, but see the notes below.
If the user's main password is also used to sign on to target applications, please note the following points:
  • The main password can only be used if the user was required to enter the password upon login. This is not the case for Kerbos and other SSO-Logins. In those cases, this option is not possible.
  • Normally, the user's password is only available directly after login. If the user comes back to the Loginapp later, e.g. to access a different application, the password is normally not available anymore.
  • If only one target application is configured, this should not be a problem, since the user only needs to be authenticated at the very beginning (directly after the authentication).
  • If the user's password is needed for several target application, then it is has to be available every time the user wants to access another application in the same session. In this case, the password should be saved in the session ticket (see Security Settings).
Attributes
String
Optional
License-Tags
SubIdentities
Example
applA_password
Example
FIXED:123456
Password Encryption Method (passwordEncryptionMethod)
Description
The type of password encryption used to decrypt this password.
Leave empty if the password is not encrypted (not recommended if the password is read from a context data field).
Attributes
Plugin-Link
Optional
License-Tags
SubIdentities
Assignable plugins
Required Roles (requiredRoles)
Description
A list of roles used to access this target application.

The user needs at least one of the roles in order to get access to the application.

If no roles are configured, all authenticated users may access the application.

The user's roles may be transformed before being compared to this list using the Role Transformation Rules (see separate property).

If the user doesn't have any of these roles, the "Step-Up Authenticators" (in Authentication Settings) are consulted in order to find out whether they can be obtained using a Step-Up.

Attributes
String-List
Optional
Airlock Gateway (WAF) Roles (airlockGatewayRoles)
Description

The Airlock Gateway (WAF) roles that should be set when accessing this target application, instead of using the users roles as Gateway roles.

The name of the role can be followed by a colon and the idle timeout of the role in seconds, e.g. "myrole:300" sets the role "myrole" that will expire after 5 minutes of client inactivity.

With a second colon and a second number, the life-time can be set, e.g. "myrole:300:3600" will set the role "myrole" for a maximum of 1 hour, but it will also expire after 5 minutes of client inactivity.

Note: If you want to replace (instead of add) target application's Gateway roles in the session upon the first visit of each target application, you have to disable the "Add Credentials To Session" flag in the "Airlock Gateway (WAF) Settings" of the Login Application.

Attributes
String-List
Optional
Role Transformation Rules (roleTransformationRules)
Description
A list of transformation rules used to modify user roles before being compared to the "Required Roles" of an application.
Attributes
Plugin-List
Optional
Assignable plugins
Propagated Roles To Delete (propagatedRolesToDelete)
Description
A list of regular expressions. Any role matching one of these expressions is not propagated to the target application, unless it also matches one of the "Propagated Roles To Keep". The matching is performed before any transformation.
Attributes
RegEx-List
Optional
Propagated Roles To Keep (propagatedRolesToKeep)
Description
A list of regular expressions. If set, only roles matching at least one of these expressions are propagated to the target application, even if they match one of the "Propagated Roles To Delete". Notice that any "Propagated Roles To Add" are always added. The matching is performed before any transformation.
Attributes
RegEx-List
Optional
Propagated Roles Transformation Rules (propagatedRolesTransformationRules)
Description
A list of transformation rules used to modify roles names that are sent to an application by the identity propagator. All transformations are applied to every role that has not been deleted before as a pipeline.
Attributes
Plugin-List
Optional
Assignable plugins
Propagated Roles To Add (propagatedRolesToAdd)
Description
The static roles that will always be added to the final list of propagated roles (no transformation is applied to those).
Attributes
String-List
Optional
YAML Template (with default values)

type: AuthenticatorBasedOneShotTargetApplication
id: AuthenticatorBasedOneShotTargetApplication-xxxxxx
displayName: 
comment: 
properties:
  airlockGatewayRoles:
  authenticator:
  credentialExtractorFactory:
  enableUserTrailLog: true
  failureResponses:
  identityPropagator:
  passwordEncryptionMethod:
  propagatedRolesToAdd:
  propagatedRolesToDelete:
  propagatedRolesToKeep:
  propagatedRolesTransformationRules:
  requiredRoles:
  roleTransformationRules:
  urlPattern:
  useDifferentPassword:
  useDifferentUsername:
  usernameTransformation: