← Back to plugin index

Selection Authenticator

Description
Authenticator that allows dynamic selection of another authenticator based on the credentials available to the user. All configured authenticators for which the user has a suitable credential are presented to the user. The user can then manually select one of the authenticators. If there is only one authenticator available it is automatically selected without user interaction. Actual authentication is only performed with the selected authenticator.
Type name
SelectionAuthenticator
Class
com.airlock.iam.core.misc.impl.authen.SelectionAuthenticator
May be used by
Properties
Selectable Authenticators (selectableAuthenticators)
Description

A map of selectable authenticators. An authenticator is only presented to the user as an option if the user actually has suitable credentials. E.g., if an SMS Authenticator is configured here but the user does not have a phone number registered, they will not be able to select SMS authentication.

On the choice page, a translated string is displayed for each option (or the key itself if no translation is available). Translation strings use the prefix "userchoicepage.option." followed by the key in lowercase as the resource name. E.g. for "MTAN" the resource name is userchoicepage.option.mtan.

Attributes
Plugin-Map
Mandatory
Assignable plugins
Always Selectable Authenticators (alwaysSelectableAuthenticators)
Description

Authenticators that are always selectable, i.e. they are always among the options presented to the user. These authenticators cannot determine whether a user has a suitable credential or not. Therefore, they must be able to handle users that have no such credential.

See the description of "Selectable Authenticators" on how the options are displayed on the choice page.

Attributes
Plugin-Map
Optional
Assignable plugins
Auto Select If One Option (autoSelectIfOneOption)
Description
If the user has only one possible selection and this flag is enabled, the selection is automatically chosen for the user. If the flag is disabled and the user has only one selection, a selection with one possibility is displayed.
Attributes
Boolean
Optional
Default value
true
User Persister (userPersister)
Description
The user persister used to load and store user information regarding a user's last selected authentication method.
Attributes
Plugin-Link
Optional
Assignable plugins
Context Data Column Last Selected Auth Method (contextDataColumnLastSelectedAuthMethod)
Description
The context data column used to persist and retrieve the user's last selected authentication method.
  • The last selected authentication method is persisted in this context data column in the database as soon as a user continues the login process from the choice page.
  • If the last selected authentication method can be retrieved from the database upon displaying the choice page, and this method is a selectable choice, it is pre-selected for the user.
  • If a choice is pre-selected, the button on the choice page to continue the login process automatically receives the focus.
  • Persistance and pre-selection of the last selected authentication method are performed only if both the user persister and this context data column are configured.
  • The last selected authentication method in the database is represented by the corresponding selectable authenticator key.
Attributes
String
Optional
Example
last_selected_auth_method
YAML Template (with default values)

type: SelectionAuthenticator
id: SelectionAuthenticator-xxxxxx
displayName: 
comment: 
properties:
  alwaysSelectableAuthenticators:
  autoSelectIfOneOption: true
  contextDataColumnLastSelectedAuthMethod:
  selectableAuthenticators:
  userPersister: