One-Shot Target Application
Target application for the flow-based one-shot access endpoint.
This is used for the "One-Shot" authentication flow of Airlock Gateway. The denied access URL is /{entry path}/rest/public/authentication/one-shot/applications/{application id}.
applicationId) authenticationFlow) responseMappers) Configurable response mappers to specifiy HTTP status code, headers and one-shot workflow for non-success responses (i.e. flow results where the flow has not competed successfully).
If no mapper is configured or none matches the flow result, a default response mapper is used: if the flow result specifies a WWW-Authenticate header, a 401 status and the specified header are sent to the client (workflow FINAL_RESPONSE), otherwise a 403 response and workflow CONTINUE are returned. For typical use cases, this should be sufficient.
airlockGatewayRoles) These are the Airlock Gateway roles (credentials) that are set after the authentication flow has successfully been completed. These roles are used on the Gateway to control the access to protected backends. If backend applications need user roles, those must be configured in the identity propagators.
Depending on the Gateway Settings, these roles either replace the current Gateway roles or are added to them (default).
identityPropagation) usernameToPropagateProvider)
type: OneShotTargetApplication
id: OneShotTargetApplication-xxxxxx
displayName:
comment:
properties:
airlockGatewayRoles:
applicationId:
authenticationFlow:
identityPropagation:
responseMappers:
usernameToPropagateProvider: