Target Applications and Authentication
defaultApplication) applications) oneShotApplications) maxFailedLogins) temporaryLockingConfig) This configuration can be enabled or disabled in each "Authentication Flow" with the setting "Enable Temporary Locking".
rememberMeConfig) Configuration enabling the Remember-Me feature. This feature allows a user to skip certain authentication steps if a valid token is presented with the request.
loginHistoryRepository) behaviorUponExistingSession) Defines what action is taken when a user already has another authenticated Airlock Gateway session when logging in or logging out. For example, this can happen if the user left a previous session without an explicit logout or attempts to authenticate multiple concurrent sessions (with different devices or browsers).
The configured behavior may depend on the user store being able to read (and write) the session ID to/from the database/directory. Verify that the corresponding column or attribute is mapped in the used user store ("Col Latest GSID" for default database plugins; "Last GSID Value Attribute" in LDAP plugins).
disableSessionBehaviorWhenRepresented) locationInterpreters) Enables the REST endpoint used for interpreting a forward location URI prior to starting an authentication flow (REST endpoint /<loginapp-uri>/rest/public/authentication/location/interpret/).
This endpoint could extract the display language or other information from the given URI so that the client can configure itself.
The order of the configured plugins is relevant. The first plugin which can handle the forward location URI is used, all remaining plugins are ignored. If no plugins are configured or no plugin can handle the provided URI, an empty interpretation result is returned.
authenticationInformationAccessibleCondition) Condition for allowing unauthenticated access to the /public/authentication endpoint. Once a user is authenticated, access to this endpoint is always allowed, regardless of this setting.
By default, access to the information endpoint is not allowed for unauthenticated users.
Security Note: If publicly available, this endpoint could be exploited for user enumeration attacks. To prevent these attacks, it is recommended that access to the endpoint is restricted to authenticated users only.
type: TargetApplications
id: TargetApplications-xxxxxx
displayName:
comment:
properties:
applications:
authenticationInformationAccessibleCondition:
behaviorUponExistingSession:
defaultApplication:
disableSessionBehaviorWhenRepresented: true
locationInterpreters:
loginHistoryRepository:
maxFailedLogins: 5
oneShotApplications:
rememberMeConfig:
temporaryLockingConfig: