← Back to plugin index

Mapping Ticket Service

Description
The mapping ticket service is a configurable ticket service.

The pieces of information to be encoded in an authentication ticket are selected from the authentee name, roles, context data as well as the additional key-value-pairs passed to the plugin.

All pieces of data selected to be stored in the ticket can be stored under a configurable name. This plugin is thus suitable for using different user ids for different receiving applications.

Type name
MappingTicketService
Class
com.airlock.iam.core.misc.util.ticket.service.MappingTicketService
May be used by
Properties
Constant Content (constantContent)
Description
Defines a list of data elements to be stored in the ticket.

Note that values selected here can be overwritten by content or additional content (see other configuration properties) using the same ticket key.

Attributes
Plugin-List
Optional
Assignable plugins
Content from Authentee (content)
Description
Defines a list of data elements to be stored in the ticket taken from the authentee. The values can be transformed using regular expression replacement patterns or a map.

The values are interpreted as follows:

  • The value @username refers to the authentee's name.
  • The value @roles refers to the authentee's roles.
  • The value @all-context-data refers to all context data of the authentee. If used, all context data entries are stored in the ticket using their own keys. The ticketKey (see other property description) is ignored for this value. Even if this special value is used, selected context data container entries can still be selected by their name (see item below).
  • All other values are used to reference a value in the context data container of the authentee.

Note that values selected here can be overwritten by additional values (see other configuration property) using the same ticket key.

Attributes
Plugin-List
Optional
Assignable plugins
Additional Content (additionalContent)
Description
This property defines values to be stored in the issued ticket taken from the list of additional key-value-pairs passed to this plugin.

The values are interpreted as follows:

  • The value @all-additional-values refers to all additional key-value-pairs provided to this plugin. If used, these values are stored in the ticket using their own keys. The ticketKey (see other property description of list elements) is ignored for this value. Even if this special value is used, selected additional values can still be selected by their name (see item below).
  • All other values are used to reference single additional value in the list of additional key-value-pairs.

Note that values selected here can overwrite values from the context data container of the authentee (see other configuration property) using the same ticket key.

Values available for identity propagation: The following values are available for identity propagation, if the corresponding feature is licensed and configured.
Values available in REST login identity propagation, when using the 'REST Identity Propagation' plugin:

  • AUTH_TIMESTAMP: the time of authentication
  • AUTH_TOKEN_ID: the auth token id as used for transaction approval
  • REPRESENTER_ID: the representer's ID, as used for user representation
Values available in the HTML login application identity propagation:
  • AUTH_TIMESTAMP: the time of authentication
  • AUTH_TOKEN_ID: the auth token id as used for transaction approval
  • AUTH_PLUGIN: the authentication plugin identifier
  • LANG: the user's language as used in the login forms
  • GSID: the global session identifier
  • CLIENT_IP: the client's IP address
  • GEOLOCATION_CITY: the geolocation city
  • GEOLOCATION_CONTINENT_CODE: the geolocation continent code
  • GEOLOCATION_COUNTRY_CODE: the geolocation country code
  • GEOLOCATION_LATITUDE: the geolocation latitude
  • GEOLOCATION_LONGITUDE: the geolocation longitude
  • GEOLOCATION_SUBDIVISION_CODE: the geolocation subdivision code
  • GEOLOCATION_TIMEZONE: the geolocation timezone
  • GEOLOCATION_ZIP: the geolocation zip
  • REPRESENTER_ID: the representer's ID, as used for user representation
  • OPENID_CONNECT_ID_TOKEN: the OpenID Connect ID Token that may have been used for the authentication.
  • OAUTH2_ACCESS_TOKEN: the OAuth 2.0 or OpenID Connect Access Token that may have been used for the authentication.

Attributes
Plugin-List
Optional
Assignable plugins
Validity Millis (validityMillis)
Description
Defines the number of milliseconds the tickets issued by this service are valid for.
Attributes
Long
Optional
Default value
28800000
YAML Template (with default values)

type: MappingTicketService
id: MappingTicketService-xxxxxx
displayName: 
comment: 
properties:
  additionalContent:
  constantContent:
  content:
  validityMillis: 28800000