← Back to plugin index

CSRF Token Extraction Step

Description

This plugin obtains the login page of a backend application with a HTTP GET request. It then extracts the CSRF-token from the login form and stores it in the on-behalf login step context under the configured key for further use.

This on behalf login step is typically used as a first step in the sequence of on-behalf login steps.

Type name
CsrfFormTokenExtractionStep
Class
com.airlock.iam.core.misc.impl.sso.onbehalflogin.CsrfFormTokenExtractionStep
May be used by
Properties
CSRF token selector (csrfTokenSelector)
Description
Collects the CSRF protection token from the web application's login page.
Attributes
Plugin-Link
Mandatory
Assignable plugins
CSRF storage key (csrfStorageKey)
Description
The extracted CSRF protection token is stored in an information storage for further on behalf login steps. This key defines the name of the key under which the value of the CSRF protection token is stored. Further on behalf login steps reference the CSRF protection token's value using this key.
Attributes
String
Mandatory
Example
csrftoken
Target Application Login Page URL (targetApplicationLoginPageUrl)
Description
URL of the target application's page to connect.
Attributes
String
Mandatory
Example
http://foo.bar.ch/login.php
Example
https://secure.ergon.ch/auth/login
Query Parameters (queryParameters)
Description
The HTTP Query parameters to be added to the target url. This implementation supports template syntax using ${variable} in parameters. Available variables are all values provided to the identity propagation.

If the query parameter is already defined in the target URL, the value defined through this configuration will be added to the existing values.

If the same parameter name is configured multiple times, the values will be added to the existing values in order of the configured list.

Attributes
Plugin-List
Optional
Assignable plugins
On Behalf Login Step Validator (onBehalfLoginStepValidator)
Description
An optional validator that validates the response of this step.
Attributes
Plugin-Link
Optional
Assignable plugins
Additional Headers (additionalHeaders)
Description
A list of headers to add to the standard headers of the HTTP client. It is possible to add multiple headers with the same name.
Attributes
Plugin-List
Optional
Assignable plugins
YAML Template (with default values)

type: CsrfFormTokenExtractionStep
id: CsrfFormTokenExtractionStep-xxxxxx
displayName: 
comment: 
properties:
  additionalHeaders:
  csrfStorageKey:
  csrfTokenSelector:
  onBehalfLoginStepValidator:
  queryParameters:
  targetApplicationLoginPageUrl: