← Back to plugin index

Context Data Username Transformer

Description
This user name transformer allows to configure any user store which provides alternative log-in names (aliases) in its context data. In case the alias is found in the context data, the provided user name will be transformed to the user ID used in the user store.
Type name
ContextDataUsernameTransformer
Class
com.airlock.iam.core.misc.impl.authen.ContextDataUsernameTransformer
May be used by
Properties
User Store (userStore)
Description
The user store which must provide the alternative user name fields (as context data). The transformation result will be the user ID of the matching user record. This user store must provide all the context data columns which are selected as potential user aliases in the context-data-columns property.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Context Data Columns (contextDataColumns)
Description
The names of the context data columns of the underlying user store which may contain an alias. The originally stated user name is looked up in all the context data columns. If there is a match, the user ID of the record in the store becomes the transformation result. If multiple records match, the user cannot log in and user trail logs are written. In this case the alias data is in an inconsistent state and this must be fixed. Thus, the listed columns - including the user ID column - must not contain duplicates.
Note that at least one context data column must be stated for the transformation to be successful.
Attributes
String-List
Mandatory
Check User Store First (checkUserStoreFirst)
Description
For efficiency reasons, the default behavior of this transformer is to first check if the user store finds a user name that matches the input of the user. With this property, this first check could be disabled.
Usually, setting this property to false is not recommended, as it is often the best strategy to first match for the user ID.
Disabling this check makes sense in a chain of UsernameTransformers where it is known that the current input name cannot be a user ID, e.g. directly after a Primary Key Lookup.
Attributes
Boolean
Optional
Default value
true
Mandatory Transformation (mandatoryTransformation)
Description
Specifies whether or not the transformation is mandatory:
This transformer serves two main purposes: It can allow login using an 'alias' in addition to the user ID (in this case, set this property to false because this transformer may or may not be given the alias) or it can transform the entered user name on the fly to an 'internal identifier' used for further processing (in this case, set this property to true). In the latter case, this 'internal identifier' cannot be used directly as a login name, thus the transformation must succeed in order to obtain a valid userid for further processing.
Note that a transformation is considered successful if the user name could be resolved, no matter whether or not the user name was actually changed (e.g. the transformation is also successful if the 'Check User Persister First' flag is true and the user name was found using that persister directly).
Attributes
Boolean
Optional
Default value
false
Stop After Successful Transformation (stopAfterSuccessfulTransformation)
Description
With this flag the chaining of user name transformers can be interrupted. If it is enabled and the user name transformer found the user name in a context field (or if enabled using the primary key lookup), following user name transformers are not executed.
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: ContextDataUsernameTransformer
id: ContextDataUsernameTransformer-xxxxxx
displayName: 
comment: 
properties:
  checkUserStoreFirst: true
  contextDataColumns:
  mandatoryTransformation: false
  stopAfterSuccessfulTransformation: false
  userStore: