← Back to plugin index

SSO Ticket Identity Propagator

Description
SSO ticket identity propagator.

Redirects to another Loginapp and provides the user ID, user roles as a query parameter (encryption strongly recommended).

This identity propagator works together with the SSO facility of the Loginapp. Using this plugin one Loginapp could play the IdP role and the other Loginapp could play the SP role in a very simple cross-domain SSO setup.

Type name
SsoTicketIdentityPropagator
Class
com.airlock.iam.core.misc.impl.sso.SsoTicketIdentityPropagator
May be used by
Properties
Ticket Parameter Name (ticketParameterName)
Description
The SSO ticket query parameter name.

To use it together with another Loginapp instance as service provider always configure sso as parameter name.

Attributes
String
Optional
Default value
sso
Example
sso
Example
ticket
Ticket Lifetime In Seconds (ticketLifetimeInSeconds)
Description
The SSO ticket lifetime in seconds.

How long should the SSO ticket be considered valid.

Attributes
Integer
Optional
Default value
5
Redirect URL (redirectUrl)
Description
The intermediate redirect URL.

Configure this if you do not want to redirect the browser to the original target URL but rather to a static URL and provide the original target URL as a query parameter.

Attributes
String
Optional
Example
https://www.test.com/medusa-login/check-login
Forward Location Parameter (forwardLocationParameter)
Description
The forward location URL parameter.

Only used if "Redirect URL" is configured and not empty.

The original target URL is appended to the "Redirect URL" as a query parameter with this name.

Attributes
String
Optional
Default value
Location
Example
Location
Encoder (encoder)
Description
The ticket encoder plugin used to sign and encrypt the SSO ticket.

Note: for browser compatibility make sure the resulting redirect URL is no longer than 2000 characters.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Additional Data Ticket Service (additionalDataTicketService)
Description
The ticket service providing additional ticket data.
Attributes
Plugin-Link
Optional
Assignable plugins
Additional Data Key Value Pairs (additionalDataKeyValuePairs)
Description
Additional fixed name-value-pairs may be provided to the ticket service.
If supported by the ticket service plugin, this is a way to add such an extra key-value-pair to a ticket.
The key-value-pairs are added to the key-value-pairs passed to this plugin by the calling application. It overwrites existing values with the same key.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: SsoTicketIdentityPropagator
id: SsoTicketIdentityPropagator-xxxxxx
displayName: 
comment: 
properties:
  additionalDataKeyValuePairs:
  additionalDataTicketService:
  encoder:
  forwardLocationParameter: Location
  redirectUrl:
  ticketLifetimeInSeconds: 5
  ticketParameterName: sso