← Back to plugin index

Fallback Authenticator

Description
Combines two or more authenticator plugins in the way that the next authenticator in the list is tried if one fails to authenticate.

The reason of "failing" can be configured (see separate properties):

  • Error during authentication process
  • User not found
  • User not valid (outside validity period or flagged as invalid)
  • Credential not assigned
  • Credential not active
  • Authentication failed (e.g. password wrong)

In general, when switching to the next authenticator, the credential object (e.g. username and password) used with the first authenticator that led to the "failure" is used again with the next authenticator. A new session is obtained from the next authenticator. After trying all authenticators, the result from the last authenticator is returned regardless of its result.

Example usage: Use the reason "user not found" if it is not clear what system to authenticate against in case of multiple user directories.

Type name
FallbackAuthenticator
Class
com.airlock.iam.core.misc.impl.authen.FallbackAuthenticator
May be used by
Properties
Failover On Error (failoverOnAuthenticationError)
Description

Enable to switch to the next authenticator if an unrecoverable error occurs.

Typical errors arise from unreachable databases or other dependent systems.

Attributes
Boolean
Optional
Default value
true
Failover If User Not Found (failoverIfUserNotFound)
Description
Enable to switch to the next authenticator if the previous returns "user not found".
Attributes
Boolean
Optional
Default value
true
Failover If User Not Valid (failoverIfUserNotValid)
Description
Enable to switch to the next authenticator if the previous returns "user not valid". This is the case if the user record has been flagged invalid or if the current point in time is outside the validity period of the account.
Attributes
Boolean
Optional
Default value
true
Failover If Credential Not Assigned (failoverIfCredentialNotAssigned)
Description
Enable to switch to the next authenticator if the previous returns "credential not assigned".
Attributes
Boolean
Optional
Default value
false
Failover If Credential Not Active (failoverIfCredentialNotActive)
Description
Enable to switch to the next authenticator if the previous returns "credential not active".
Attributes
Boolean
Optional
Default value
false
Failover If Authentication Fails (failoverIfAuthenticationFails)
Description
Enable to switch to the next authenticator on arbitrary authentication failures (e.g. password wrong).
Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: FallbackAuthenticator
id: FallbackAuthenticator-xxxxxx
displayName: 
comment: 
properties:
  authenticators:
  failoverIfAuthenticationFails: false
  failoverIfCredentialNotActive: false
  failoverIfCredentialNotAssigned: false
  failoverIfUserNotFound: true
  failoverIfUserNotValid: true
  failoverOnAuthenticationError: true