On Behalf Login Identity Propagator
Description
This identity propagator performs a login 'on behalf' of the user at a backend web application. It performs the necessary login steps to obtain an authenticated session from login into the backend application. Then it attaches the session cookie to the user's authenticated session, thus enabling access to the backend application.
The login process is configured as a sequence of on behalf login steps. Each on behalf login step performs a HTTP operation and can store newly gathered information in an information storage for the next step.
For example: A first on behalf login step executes a HTTP GET request on the web application's login page and extracts the CSRF protection token. A next on behalf login step submits the login form with username, password and the extracted CSRF token.
Note that on behalf logins are not robust against changes of the web application. Therefore we recommend this identity propagation mechanism only for legacy application that do not provide another way for identity propagation.
May be used by
Properties
HTTP Client (
httpClientConfig) Description
The HTTP client that connects to the web application.
Attributes
Plugin-Link
Mandatory
Assignable plugins
On Behalf Login Steps (
onBehalfLoginSteps) Description
Sequence of on behalf login steps that are performed to simulate the user's login process.
Attributes
Plugin-List
Mandatory
Assignable plugins
Cookies (
cookies) Description
A list of cookies that are expected from the web application and that propagated. Usually the only cookie to configure is the session cookie.
Attributes
Plugin-List
Mandatory
Assignable plugins
Forward User To Last Redirect Location (
forwardUserToLastRedirectLocation) Description
If set, the user will be forwarded to the URL specified in the
Note 1: The URL must match at least one regex in the allowedForwardLocationPatterns (see below).
Note 2: If set, the forward location sent in the response of the last onBehalfLoginStep is not followed.
Note 3: If set and the response to the last onBehalfLoginStep does not contain a Location header, the user is forwarded to the default forward location.
Location header in the response of the last onBehalfLoginStep.
Note 1: The URL must match at least one regex in the allowedForwardLocationPatterns (see below).
Note 2: If set, the forward location sent in the response of the last onBehalfLoginStep is not followed.
Note 3: If set and the response to the last onBehalfLoginStep does not contain a Location header, the user is forwarded to the default forward location.
Attributes
Boolean
Optional
Default value
false
Allowed Forward Location Patterns (
allowedForwardLocationPatterns) Description
A list of regular expressions defining the allowed forward locations in the response of the last onBehalfLoginStep.
This setting is only relevant if
This setting is only relevant if
forwardUserToLastRedirectLocation is set to true. In that case the forward location must match at least one regex in order to be accepted. If the forward location does not match any regex, the default forward location is used.
- Notice that the forward location will always be an absolute URL, relative URLs are not supported.
- Notice that the forward location is from the on behalf HTTP clients perspective, which might be different from the users perspective, if IAM is behind the Airlock Gateway (WAF). This is because the Airlock Gateway may rewrite the forward location.
- Note that URLs with any 'User Information' part in front of the host name (for example "https://user@domain.com/") are never accepted.
Attributes
RegEx-List
Optional
YAML Template (with default values)
type: OnBehalfLoginIdentityPropagator
id: OnBehalfLoginIdentityPropagator-xxxxxx
displayName:
comment:
properties:
allowedForwardLocationPatterns:
cookies:
forwardUserToLastRedirectLocation: false
httpClientConfig:
onBehalfLoginSteps: