← Back to plugin index

HTTP Password Service

Description
Perform a password change operation by sending a HTTP POST request to a configured URL. Only the changePassword operation is supported. Additional parameters may be sent to the password change URL, either static values or user attributes.
Type name
HttpPasswordService
Class
com.airlock.iam.core.misc.impl.authen.HttpPasswordService
May be used by
Properties
Password Change URL (passwordChangeUrl)
Description
The full URL of the application that provides the password change functionality. A POST request is sent to this URL simulating a login.
See note in plug-in description when using SSL (HTTPS instead of HTTP).
Attributes
String
Mandatory
Example
http://someapp.somehost.com/auth/passwordchange
Example
https://securehost.com/changepassword.php
HTTP Parameter Username (httpParamUsername)
Description
The name of the HTTP parameter for the username.
Attributes
String
Mandatory
Example
uid
Example
userId
Example
username
Example
contractNo
User Persister (userPersister)
Description
User persister that is used to load the user data so that user attributes can be passed on to the password change URL.
Attributes
Plugin-Link
Optional
Assignable plugins
User Data Parameters (userDataParams)
Description
List of user record values that are sent with the request when changing the password.
Attributes
Plugin-List
Optional
Assignable plugins
Static Parameters (staticParams)
Description
List of fixed (statically defined) HTTP parameters that are sent with the request when changing the password.

In many cases, the submit button value must be sent to an application to make it think that the button has been pressed.

Attributes
Plugin-List
Optional
Assignable plugins
HTTP Parameter Old Password (httpParamOldPassword)
Description
The name of the HTTP parameter for the old password.
Attributes
String
Mandatory
Example
oldpassword
Example
existingpassphrase
HTTP Parameter New Password (httpParamNewPassword)
Description
The name of the HTTP parameter for the new password.
Attributes
String
Mandatory
Example
password
Example
passphrase
Expected Response Status Code (expectedResponseStatusCode)
Description
The expected HTTP response code that signals a successful password change.

The response status code is always being checked on password changes. A password change is successful if the response status code equals the expected status code. Additionally a pattern can be searched in the response body using the "expected response body pattern" configuration property.

Attributes
Integer
Optional
Default value
200
Expected Response Body Pattern (expectedResponseBodyPattern)
Description
A pattern that is searched in the response to the password change request. If this property is set the pattern will be searched in the response body in addition to the response status code check.
Attributes
RegEx
Optional
Allow Only Trusted Certs (allowOnlyTrustedCerts)
Description

Only allow connections to servers whose certificate is trusted. See documentation of property "Trust Store Path" for more information about what certificates are trusted.

Security warning: Trusting all certificates allows connections to adversarial hosts. Only disable this property for testing and integration setups.

Attributes
Boolean
Optional
Default value
true
Verify Server Hostname (verifyServerHostname)
Description

Enables hostname verification, i.e. the actual hostname must be the same as in the server certificate.

Security warning: Not verifying the hostname may allow connections to adversarial hosts, e.g. if they employ DNS spoofing. Only disable this property for testing and integration setups.

Attributes
Boolean
Optional
Default value
true
Trust Store Path (trustStorePath)
Description
Keystore file name containing trusted certificate issuers (and trusted certificates).

If this property is not defined the following certificate issuers are trusted:

  • The list of issuers known to the Java VM if the system property "javax.net.ssl.trustStore" is not defined.
  • The list of issuers in a keystore referenced by system property "javax.net.ssl.trustStore" if defined in instance.properties using iam.java.opts

If this property is defined then the following certificate issuers are trusted:

  • The list of issuers in the referenced truststore file and no others.

This property is only relevant if the property "Allow Only Trusted Certs" is enabled.

Attributes
File/Path
Optional
Trust Store Type (trustStoreType)
Description
Identifies the type of the keystore.
Attributes
String
Optional
Default value
JKS
Allowed values
JKS, PKCS12
Trust Store Password (trustStorePassword)
Description
The password used to verify the authenticity of the trust store.

Depending on the keystore type, leaving this property empty (or undefined) has a different effect:

  • JKS: the keystore can be opened and used but the integrity of the keystore is not checked.
  • PKCS12: an error occurs.

Attributes
String
Optional
Sensitive
Connect/Read Timeout [s] (connectTimeout)
Description
The connection and read timeout in seconds. A timeout value of zero is interpreted as 60 seconds.
Attributes
Integer
Optional
Default value
10
Correlation ID Header Name (correlationIdHeaderName)
Description

When configured, all requests sent contain a header with the correlation ID with the configured name. If no value or an empty value is specified, the correlation ID header is not sent.

If the correlation ID is not defined, the correlation ID header is not included in sent requests.

Attributes
String
Optional
Validation RegEx: [a-zA-Z0-9_-]+
Suggested values
X-Correlation-ID
Proxy Host (proxyHost)
Description
The hostname of the HTTP proxy server (if any).
Attributes
String
Optional
Example
proxy.company.com
Proxy Port (proxyPort)
Description
The port of the HTTP proxy server (if any).
Attributes
Integer
Optional
Proxy Login User (proxyLoginUser)
Description
Username for the HTTP proxy if proxy authentication is used.
Attributes
String
Optional
Proxy Login Password (proxyLoginPassword)
Description
Password for the HTTP proxy if proxy authentication is used.
Attributes
String
Optional
Sensitive
YAML Template (with default values)

type: HttpPasswordService
id: HttpPasswordService-xxxxxx
displayName: 
comment: 
properties:
  allowOnlyTrustedCerts: true
  connectTimeout: 10
  correlationIdHeaderName:
  expectedResponseBodyPattern:
  expectedResponseStatusCode: 200
  httpParamNewPassword:
  httpParamOldPassword:
  httpParamUsername:
  passwordChangeUrl:
  proxyHost:
  proxyLoginPassword:
  proxyLoginUser:
  proxyPort:
  staticParams:
  trustStorePassword:
  trustStorePath:
  trustStoreType: JKS
  userDataParams:
  userPersister:
  verifyServerHostname: true