← Back to plugin index

Credential-based Authenticator Selector

Description

An authenticator plugin that selects one of several authenticators (and/or contexts) depending on the credential provided in the first or any preceding authentication steps: The credential, i.e. the token or response to a challenge or the password, is compared against a list of regular expressions. The first matching expression defines the authenticator plugin (and/or context) to use for the rest of the authentication process. If none matches, a default authenticator is used.

This plugin does not add or change data added to the authentication result but just passes on the results of the wrapped authenticator(s).

Example usage:

  • Use the plugin as second authenticator after username and password have been provided.
  • Configure it with an SmsAuthenticator as default authenticator and an EmailOtpAuthenticator used if the token matches "email"
  • The user is then asked for an SMS code after successful password verification. If the user enters "email" as SMS code, an email is sent and the user is asked for the OTP in the email.

Type name
CredentialBasedAuthenticatorSelector
Class
com.airlock.iam.core.misc.impl.authen.CredentialBasedAuthenticatorSelector
May be used by
Properties
Mappings (mappings)
Description
Mappings between user name patterns and authenticator plugins.
Attributes
Plugin-List
Mandatory
Assignable plugins
YAML Template (with default values)

type: CredentialBasedAuthenticatorSelector
id: CredentialBasedAuthenticatorSelector-xxxxxx
displayName: 
comment: 
properties:
  defaultAuthenticator:
  mappings: