Airlock Gateway Settings
addCredentialsToSession) ADD_CREDENTIALS. If every identity propagation shall replace all previously set roles, disable this property, which results in the Airlock Control Cookie command SET_CREDENTIALS. controlCookieName) The name of the control cookie used to communicate with the Airlock Gateway (WAF) backend control API. This must be the same as configured in Airlock.
A control cookie is set after successful authentication with the roles granted to the user as credentials/roles. Additionally, a new session ID is generated (to prevent session fixation attacks) and the global session ID is set as audit token.
This property also enables so-called "session tickets". After successful authentication the user's name and the granted roles are stored in the current session plus a session ticket cookie including this information is stored in the Airlock Gateway cookie store. The session ticket is needed to re-authenticate any new session later.
environmentCookiePrefix) auditToken) Type of the audit token set in the Airlock Gateway (WAF) after the authentication.
- "Username": The audit token contains just the username.
- "SessionID": The audit token contains just the session id.
- "Username and SessionID": The audit token contains the username followed by a "-" and the session ID.
- "None": The audit token is empty.
type: AirlockGateway
id: AirlockGateway-xxxxxx
displayName:
comment:
properties:
addCredentialsToSession: true
auditToken: USERNAME
controlCookieName: AL_CONTROL
environmentCookiePrefix: AL_ENV_