HTTP Basic Auth Identity Propagator
Description
An identity propagator that instructs the Airlock Gateway (WAF) to send an HTTP Basic Auth header to the back-end.
This propagator only works together with Airlock Gateway (WAF). It uses the control API to propagate username and password.
May be used by
Properties
Control Cookie Name (
controlCookieName) Description
The name of the Airlock control cookie. The name must match the control cookie name defined in the Airlock server.
Attributes
String
Optional
Default value
AL_CONTROL
Suggested values
AL_CONTROL
Username Property (
usernameProperty) Description
The username to be used for identity propagation.
Possible values are:- The special keyword "
@username" to use the effective username of the authenticated user. - The prefix "
STATIC:..." to use a fixed value every time. The part after the prefix "STATIC:" is used for all users.
For example: "STATIC:techaccount" means that the username "techaccount" is used for all users. - The name of a context data field read from persistency (for example "
context_data"). Make sure to also configure the same value in the persister.
Attributes
String
Optional
Default value
@username
Example
@username
Example
STATIC:techaccount
Example
context_data
Example
userPrincipalName
Password Property (
passwordProperty) Description
The name of the context key holding the password to be used for identity propagation. It only works if the password is stored in the session ticket (must be activated in the Security Settings).
Possible values are:- The special keyword "
@password" to use the password the user entered during authentication.
Note that depending on the authentication scheme, there is no such password (e.g. when using client certificates). - The special keyword "
@roles" to use the user's roles as the password. The roles are represented as comma-separated list (e.g. "admin,empoloyee,user").
Notice: If there are users with no roles and basic-auth headers with no passwords are accepted by the backend, the property "Allow Empty Passwords" must be enabled. - The prefix "
STATIC:..." to use a fixed value every time. The part after the prefix "STATIC:" is used for all users.
For example: "STATIC:techpwd" means that the password "techpwd" is used for all users. - The name of a context data field read from persistency (for example "
context_data"). Make sure to also configure the same value in the persister.
Attributes
String
Optional
Default value
@password
Example
@password
Example
STATIC:techpwd
Example
@roles
Example
context_data
Example
userPrincipalName
Allow Empty Passwords (
allowEmptyPasswords) Description
If enabled, empty passwords are accepted and propagated. Only enable this option if your backend is able to handle such basic-auth headers.
Attributes
Boolean
Optional
Default value
false
Encoding (
encoding) Description
The encoding used for the basic auth header values. The default is to use UTF-8, but certain webservers might expect ISO-8859-1.
Attributes
String
Optional
Default value
UTF-8
Suggested values
UTF-8, ISO-8859-1, ISO-8859-15
Target Mapping Name (
targetMappingName) Description
The basic auth header can be restricted to just one back-end by specifying its name here. If left unset, the basic auth header is sent to every back-end having the 'on-behalf' login configured.
Attributes
String
Optional
YAML Template (with default values)
type: HttpBasicAuthIdentityPropagator
id: HttpBasicAuthIdentityPropagator-xxxxxx
displayName:
comment:
properties:
allowEmptyPasswords: false
controlCookieName: AL_CONTROL
encoding: UTF-8
passwordProperty: @password
targetMappingName:
usernameProperty: @username