Role-based Authenticator Selector
Description
Authenticator plugin that selects one of several configured authenticators depending on the user roles granted before the authentication process. The user roles are compared against a list of mappings. One mapping consists of a list of roles and an authenticator. The first mapping containing a role of the user defines the authenticator to be used for the rest of the authentication process.
If no mapping matches, the default authenticator is used.
Note: This plugin does not check the status of the user account (locked, invalid) and does not update login statistics (failed logins, etc.). It can therefore only be used in conjunction with another authenticator (e.g. Main Authenticator or Meta Authenticator).
May be used by
Properties
Mappings (
mappings) Description
Ordered list of mappings between user roles and authenticators. The first matching mapping is chosen for the authentication process.
Attributes
Plugin-List
Mandatory
Assignable plugins
Default Authenticator (
defaultAuthenticator) Description
The authenticator to use when none of the defined mappings match the roles of the user to authenticate.
Attributes
Plugin-Link
Mandatory
Assignable plugins
Accepting Authenticator Airlock 2FA Authenticator Auth Method-based Authenticator Selector Credential-based Authenticator Selector Denying Authenticator Dummy Matrix Authenticator Dummy Two Step Authenticator Email Otp Authenticator MTAN/SMS Authenticator Matrixcard Authenticator (TAN Challenge) OATH OTP Authenticator RADIUS Authenticator Role-based Authenticator Selector Selection Authenticator Static Authenticator Token Authenticator
User Persister (
userPersister) Description
The user persister used to load the user's roles.
Attributes
Plugin-Link
Mandatory
Assignable plugins
YAML Template (with default values)
type: RoleBasedAuthenticatorSelector
id: RoleBasedAuthenticatorSelector-xxxxxx
displayName:
comment:
properties:
defaultAuthenticator:
mappings:
userPersister: