← Back to plugin index

Access Cookie Identity Propagator

Description
An identity propagator that obtains an access cookie from another web application and uses it for identity propagation.

This plugin performs a HTTP POST request with the username and the password the user entered on a login form to the configured application and it expects this application to set an access cookie. This access cookie is then set to the response object involved in the identity propagation process.

This plugin requires that the caller of the identity propagator puts the username and the password into the parameter map. The username must be stored under the key USERNAME and the password under the key PASSWORD.

The plugin is thought to be used in situations where there is a legacy application providing access cookies after a weak authentication process (username and password) and these access cookie should be used in a different authenticaiton process for telling other legacy applications (that are "used to" the access cookie) about the authenticated user.

Type name
AccessCookieIdentityPropagator
Class
com.airlock.iam.core.misc.impl.sso.AccessCookieIdentityPropagator
May be used by
Properties
Access Cookie Source URL (accessCookieSourceUrl)
Description
The full URL of the application that provides the access cookies. A POST request is sent to this URL simulating a login.
See note in plug-in description when using SSL (HTTPS instead of HTTP).
Attributes
String
Mandatory
Example
http://someapp.somehost.com/auth/login
Example
https://securehost.com/login.php
HTTP Parameter Username (httpParamUsername)
Description
The name of the HTTP parameter for the username.
Attributes
String
Mandatory
Example
uid
Example
userId
Example
username
Example
contractNo
HTTP Parameters (httpParams)
Description
List of fixed (statically defined) HTTP parameters that are sent with the request when obtaining an access cookie.

In many cases, the submit button value must be sent to an application to make it think that the button has been pressed.

Attributes
Plugin-List
Optional
Assignable plugins
HTTP Parameter Password (httpParamPassword)
Description
The name of the HTTP parameter for the password.
Attributes
String
Mandatory
Example
password
Example
passphrase
Allow Only Trusted Certs (allowOnlyTrustedCerts)
Description

Only allow connections to servers whose certificate is trusted. See documentation of property "Trust Store Path" for more information about what certificates are trusted.

Security warning: Trusting all certificates allows connections to adversarial hosts. Only disable this property for testing and integration setups.

Attributes
Boolean
Optional
Default value
true
Verify Server Hostname (verifyServerHostname)
Description

Enables hostname verification, i.e. the actual hostname must be the same as in the server certificate.

Security warning: Not verifying the hostname may allow connections to adversarial hosts, e.g. if they employ DNS spoofing. Only disable this property for testing and integration setups.

Attributes
Boolean
Optional
Default value
true
Trust Store Path (trustStorePath)
Description
Keystore file name containing trusted certificate issuers (and trusted certificates).

If this property is not defined the following certificate issuers are trusted:

  • The list of issuers known to the Java VM if the system property "javax.net.ssl.trustStore" is not defined.
  • The list of issuers in a keystore referenced by system property "javax.net.ssl.trustStore" if defined in instance.properties using iam.java.opts

If this property is defined then the following certificate issuers are trusted:

  • The list of issuers in the referenced truststore file and no others.

This property is only relevant if the property "Allow Only Trusted Certs" is enabled.

Attributes
File/Path
Optional
Trust Store Type (trustStoreType)
Description
Identifies the type of the keystore.
Attributes
String
Optional
Default value
JKS
Allowed values
JKS, PKCS12
Trust Store Password (trustStorePassword)
Description
The password used verify the authenticity of the trust store.

Depending on the keystore type, leaving this property empty (or undefined) has a different effect:

  • In keystores like JKS, the keystore can be opened and used but the integrity of the keystore is not checked.
  • In keystores like PKCS12, the keystore cannot be opened an an error occurs.

Attributes
String
Optional
Sensitive
Connect/Read Timeout [s] (connectTimeout)
Description
The connection and read timeout in seconds. A timeout value of zero is interpreted as 60 seconds.
Attributes
Integer
Optional
Default value
10
Correlation ID Header Name (correlationIdHeaderName)
Description

When configured, all requests sent contain a header with the correlation ID with the configured name. If no value or an empty value is specified, the correlation ID header is not sent.

If the correlation ID is not defined, the correlation ID header is not included in sent requests.

Attributes
String
Optional
Validation RegEx: [a-zA-Z0-9_-]+
Suggested values
X-Correlation-ID
Proxy Host (proxyHost)
Description
The hostname of the HTTP proxy server (if any).
Attributes
String
Optional
Example
proxy.company.com
Proxy Port (proxyPort)
Description
The port of the HTTP proxy server (if any).
Attributes
Integer
Optional
Proxy Login User (proxyLoginUser)
Description
Username for the HTTP proxy if proxy authentication is used.
Attributes
String
Optional
Proxy Login Password (proxyLoginPassword)
Description
Password for the HTTP proxy if proxy authentication is used.
Attributes
String
Optional
Sensitive
Cookies (cookies)
Description
A list of cookies to expect and send back to the client.
Attributes
Plugin-List
Mandatory
Assignable plugins
YAML Template (with default values)

type: AccessCookieIdentityPropagator
id: AccessCookieIdentityPropagator-xxxxxx
displayName: 
comment: 
properties:
  accessCookieSourceUrl:
  allowOnlyTrustedCerts: true
  connectTimeout: 10
  cookies:
  correlationIdHeaderName:
  httpParamPassword:
  httpParamUsername:
  httpParams:
  proxyHost:
  proxyLoginPassword:
  proxyLoginUser:
  proxyPort:
  trustStorePassword:
  trustStorePath:
  trustStoreType: JKS
  verifyServerHostname: true