← Back to plugin index

Target Application

Description
Specification of authentication, authorization and identity propagation for an application to be protected by Airlock IAM.
Type name
TargetApplication
Class
com.airlock.iam.authentication.application.configuration.targetapp.TargetApplicationConfig
May be used by
Properties
Application ID (applicationId)
Description
Unique ID of this application. The ID must be used in the authorization endpoint to indicate that access to this application is requested.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Application Selector (applicationSelector)
Description
Instead of the application ID, an URI might be used in the authorization endpoint to indicate that access to this application is requested.

The first application that matches the forward URI is used.

The selector is ignored for the default application, which is always used when none of the other applications match.

In combination with Authorization Conditions in Protected Self-Service Flows, the Application Selector can be used to trigger step-up authentication.

Attributes
Plugin-Link
Optional
Assignable plugins
Authentication Flow (authenticationFlow)
Description
The authentication flow determines the user identity and awards tags to the user session for completed authentication steps. After successful completion of the authentication flow, the user is considered identified and the tags are awarded, but identity propagation will not be performed until the authorization flow is also completed successfully.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Authorization Flow (authorizationFlow)
Description
The authorization flow that comes after successful completion of the authentication flow. Identity propagation and awarding of Airlock Gateway roles are only done once the authorization is successfully completed.
Attributes
Plugin-Link
Optional
Assignable plugins
Airlock Gateway Roles (airlockGatewayRoles)
Description

These are the Airlock Gateway roles (credentials) that are set after the authentication flow and the corresponding authorization flow (if configured) have successfully been completed. These roles are used on the Gateway to control the access to protected backends. If backend applications need user roles, those must be configured in the identity propagators.

Depending on the Gateway Settings, these roles either replace the current Gateway roles or are added to them (default).

Attributes
Plugin-List
Optional
Assignable plugins
Identity Propagation (identityPropagation)
Description
Identity propagators add cookies and/or headers to the response after successful authorization. The identity propagators are applied in the order in which they are configured.
Attributes
Plugin-List
Optional
Assignable plugins
Username To Propagate Provider (usernameToPropagateProvider)
Description
Provides a value to be propagated to the backend applications by the identity propagators.
Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: TargetApplication
id: TargetApplication-xxxxxx
displayName: 
comment: 
properties:
  airlockGatewayRoles:
  applicationId:
  applicationSelector:
  authenticationFlow:
  authorizationFlow:
  identityPropagation:
  usernameToPropagateProvider: