Credential-based Authenticator Selector
Description
An authenticator plugin that selects one of several authenticators (and/or contexts) depending on the credential provided in the first or any preceding authentication steps: The credential, i.e. the token or response to a challenge or the password, is compared against a list of regular expressions. The first matching expression defines the authenticator plugin (and/or context) to use for the rest of the authentication process. If none matches, a default authenticator is used.
This plugin does not add or change data added to the authentication result but just passes on the results of the wrapped authenticator(s).
Example usage:
- Use the plugin as second authenticator after username and password have been provided.
- Configure it with an SmsAuthenticator as default authenticator and an EmailOtpAuthenticator used if the token matches "email"
- The user is then asked for an SMS code after successful password verification. If the user enters "email" as SMS code, an email is sent and the user is asked for the OTP in the email.
May be used by
Administrators Configuration Meta Authenticator Meta Authenticator Meta Authenticator Persister Password Service Authenticator-based One-Shot Target Application User to Authenticator Mapping Authentication Method Identifier Mapping Fallback Authenticator Main Authenticator Auth Method-based Authenticator Selector Credential to Authenticator Mapping Radius Authentication Service Roles-to-Authenticator Mapping Role-based Authenticator Selector User-based Authenticator Selector
Properties
Mappings (
mappings) Description
Mappings between user name patterns and authenticator plugins.
Attributes
Plugin-List
Mandatory
Assignable plugins
Default Authenticator (
defaultAuthenticator) Description
The default authenticator plugin, i.e. the authenticator to be used when the credential data matches no pattern.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Accepting Authenticator Airlock 2FA Authenticator Auth Method-based Authenticator Selector Credential-based Authenticator Selector Denying Authenticator Dummy Matrix Authenticator Dummy Two Step Authenticator Email Otp Authenticator MTAN/SMS Authenticator Matrixcard Authenticator (TAN Challenge) OATH OTP Authenticator RADIUS Authenticator Role-based Authenticator Selector Selection Authenticator Static Authenticator Token Authenticator
YAML Template (with default values)
type: CredentialBasedAuthenticatorSelector
id: CredentialBasedAuthenticatorSelector-xxxxxx
displayName:
comment:
properties:
defaultAuthenticator:
mappings: