Default Authentication Processors
Description
This plugin automatically configures a list of essential flow processors for authentication flows.
The processors are configured in this order:
- CAPTCHA Processor
- User Identification Processor
- Latest Authentication Feedback Processor (only if enabled)
- Default Authentication Processor
- Factor Use Reporting Processor
- Failed Factor Attempts Processor (with strict counting)
- Renew Session ID Processor
- User Validity Processor
- Login History Processor (only if enabled)
- Unlock Attempts Reset Processor
- Device Usage Processor
- Set UI Tenant ID Processor
May be used by
Properties
Add Latest Authentication Feedback (
addLatestAuthenticationFeedback) Description
If enabled, adds the "Latest Authentication Feedback Processor" to the list of authentication processors.
The latest authentication information is provided in all flow step results (REST responses) after successfully identifying the user. In addition, the Loginapp UI displays this information on selected second factor pages.
The latest authentication information is provided in all flow step results (REST responses) after successfully identifying the user. In addition, the Loginapp UI displays this information on selected second factor pages.
Note: If an authentication flow starts with a user identifying step without verification of an authentication factor (e.g. password, remember-me cookie, SSO ticket, ...) this may lead to unwanted information leakage.
Attributes
Boolean
Optional
Default value
false
Write Login History (
writeLoginHistory) Description
If enabled, an entry is added to the login history repository after a successful authentication in an authentication flow. Within a session, only a single entry is written into the login history database per successful login, even if a user completes the same or another authentication flow multiple times. This adds the "Login History Processor" to the list of authentication processors.
Attributes
Boolean
Optional
Default value
false
Update Login Statistics (
updateLoginStatistics) Description
Login statistics (timestamps, login counts, etc.) are updated whenever a user successfully completes the first authentication flow of a session. Upon completing additional authentication flows in the same session (e.g. step-ups), the statistics are not updated.
If disabled, the login statistics are never updated when completing this flow.
Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)
type: DefaultAuthenticationProcessors
id: DefaultAuthenticationProcessors-xxxxxx
displayName:
comment:
properties:
addLatestAuthenticationFeedback: false
updateLoginStatistics: true
writeLoginHistory: false