← Back to plugin index

Target Applications and Authentication

Description
Configuration of target applications including authentication and authorization flows.
Type name
TargetApplications
Class
com.airlock.iam.authentication.application.configuration.targetapp.TargetApplicationsConfig
May be used by
Properties
Default Application (defaultApplication)
Description
The default application that is selected if a user/client directly accesses an authentication flow resource without explicitly selecting a flow by using the authorization resource.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Applications (applications)
Description
List of other protected applications. The default application must not be part of this list.
Attributes
Plugin-List
Optional
Assignable plugins
One-Shot Applications (oneShotApplications)
Description
Applications to be accessed via the one-shot access endpoint.
Attributes
Plugin-List
Optional
Assignable plugins
Max Failed Factor Attempts (maxFailedLogins)
Description
Maximal number of allowed login attempts. The user is locked if the number of failed attempts for some credential exceeds this limit.
Attributes
Integer
Optional
Default value
5
Temporary Locking (temporaryLockingConfig)
Description
Locks users temporarily after unsuccessful authentication attempts. This helps to prevent password brute force attacks.

This configuration can be enabled or disabled in each "Authentication Flow" with the setting "Enable Temporary Locking".

Attributes
Plugin-Link
Optional
Assignable plugins
Remember-Me Settings (rememberMeConfig)
Description

Configuration enabling the Remember-Me feature. This feature allows a user to skip certain authentication steps if a valid token is presented with the request.

Attributes
Plugin-Link
Optional
Assignable plugins
Login History Repository (loginHistoryRepository)
Description
Repository to store the history of successful logins. Login history entries are only written in flows where the corresponding flow processor is enabled.
Attributes
Plugin-Link
Optional
Assignable plugins
Behavior Upon Existing Session (behaviorUponExistingSession)
Description

Defines what action is taken when a user already has another authenticated Airlock Gateway session when logging in or logging out. For example, this can happen if the user left a previous session without an explicit logout or attempts to authenticate multiple concurrent sessions (with different devices or browsers).

The configured behavior may depend on the user store being able to read (and write) the session ID to/from the database/directory. Verify that the corresponding column or attribute is mapped in the used user store ("Col Latest GSID" for default database plugins; "Last GSID Value Attribute" in LDAP plugins).

Attributes
Plugin-Link
Optional
Assignable plugins
Disable Session Behavior When Represented (disableSessionBehaviorWhenRepresented)
Description
Disables the "Behavior Upon Existing Session" for represented sessions: no stored session IDs are updated, nor are existing sessions terminated. This prevents any interference with regular sessions from the represented user.
Attributes
Boolean
Optional
Default value
true
Location Interpreters (locationInterpreters)
Description

Enables the REST endpoint used for interpreting a forward location URI prior to starting an authentication flow (REST endpoint /<loginapp-uri>/rest/public/authentication/location/interpret/).

This endpoint could extract the display language or other information from the given URI so that the client can configure itself.

The order of the configured plugins is relevant. The first plugin which can handle the forward location URI is used, all remaining plugins are ignored. If no plugins are configured or no plugin can handle the provided URI, an empty interpretation result is returned.

Attributes
Plugin-List
Optional
Assignable plugins
Authentication Information Accessible Condition (authenticationInformationAccessibleCondition)
Description

Condition for allowing unauthenticated access to the /public/authentication endpoint. Once a user is authenticated, access to this endpoint is always allowed, regardless of this setting.

By default, access to the information endpoint is not allowed for unauthenticated users.

Security Note: If publicly available, this endpoint could be exploited for user enumeration attacks. To prevent these attacks, it is recommended that access to the endpoint is restricted to authenticated users only.

Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: TargetApplications
id: TargetApplications-xxxxxx
displayName: 
comment: 
properties:
  applications:
  authenticationInformationAccessibleCondition:
  behaviorUponExistingSession:
  defaultApplication:
  disableSessionBehaviorWhenRepresented: true
  locationInterpreters:
  loginHistoryRepository:
  maxFailedLogins: 5
  oneShotApplications:
  rememberMeConfig:
  temporaryLockingConfig: