← Back to plugin index

Fallback Request Authentication

Description

Combines multiple request authentications and tries them one after another. The first authentication that recognizes a credential in the request terminates the chain: its result (success or failure) is returned and no further authentication is tried. If no authentication recognizes a credential, the request is rejected as unauthenticated.

This is useful when a REST API must accept credentials from independent sources.

Type name
FallbackRequestAuthentication
Class
com.airlock.iam.common.application.configuration.credential.FallbackRequestAuthenticationConfig
May be used by
Properties
Request Authentications (requestAuthentications)
Description

The request authentications to try, in order. The first one that recognizes a credential in the request is authoritative.

Important: the configured authentications must recognize different credentials so that all but the matching one return an empty result for a given request. Authentications that read the same credential input (for example two 'Basic Auth' authentications with different password repositories) cannot be combined: the first one already recognizes the credential and, if it does not accept it, blocks the request and increments its failure counters instead of falling through to the next one.

A 'Denying Request Authentication' rejects every request and therefore ends the chain, so generally it should not be used here.

Attributes
Plugin-List
Mandatory
Assignable plugins
YAML Template (with default values)

type: FallbackRequestAuthentication
id: FallbackRequestAuthentication-xxxxxx
displayName: 
comment: 
properties:
  requestAuthentications: