← Back to plugin index

One-Shot Target Application

Description

Target application for the flow-based one-shot access endpoint.

This is used for the "One-Shot" authentication flow of Airlock Gateway. The denied access URL is /{entry path}/rest/public/authentication/one-shot/applications/{application id}.

Type name
OneShotTargetApplication
Class
com.airlock.iam.authentication.application.configuration.targetapp.OneShotTargetApplicationConfig
May be used by
Properties
Application ID (applicationId)
Description
Unique ID of this application. This ID is used in the "access" endpoint to select the target application.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Authentication Flow (authenticationFlow)
Description
The authentication flow determines the user identity and awards tags to the user session for completed authentication steps. After successful completion of the authentication flow, the user is considered identified and the tags are awarded and identity propagation will be performed.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Response Mappers (responseMappers)
Description

Configurable response mappers to specifiy HTTP status code, headers and one-shot workflow for non-success responses (i.e. flow results where the flow has not competed successfully).

If no mapper is configured or none matches the flow result, a default response mapper is used: if the flow result specifies a WWW-Authenticate header, a 401 status and the specified header are sent to the client (workflow FINAL_RESPONSE), otherwise a 403 response and workflow CONTINUE are returned. For typical use cases, this should be sufficient.

Attributes
Plugin-List
Optional
Assignable plugins
Airlock Gateway Roles (airlockGatewayRoles)
Description

These are the Airlock Gateway roles (credentials) that are set after the authentication flow has successfully been completed. These roles are used on the Gateway to control the access to protected backends. If backend applications need user roles, those must be configured in the identity propagators.

Depending on the Gateway Settings, these roles either replace the current Gateway roles or are added to them (default).

Attributes
Plugin-List
Optional
Assignable plugins
Identity Propagation (identityPropagation)
Description
Identity propagators add cookies and/or headers to the response after successful authentication. The identity propagators are applied in the order in which they are configured.
Attributes
Plugin-List
Optional
Assignable plugins
Username To Propagate Provider (usernameToPropagateProvider)
Description
Provides a value to be propagated to the backend applications by the identity propagators.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: OneShotTargetApplication
id: OneShotTargetApplication-xxxxxx
displayName: 
comment: 
properties:
  airlockGatewayRoles:
  applicationId:
  authenticationFlow:
  identityPropagation:
  responseMappers:
  usernameToPropagateProvider: