Mapping Ticket Service
The pieces of information to be encoded in an authentication ticket are selected from the authentee name, roles, context data as well as the additional key-value-pairs passed to the plugin.
All pieces of data selected to be stored in the ticket can be stored under a configurable name. This plugin is thus suitable for using different user ids for different receiving applications.
constantContent) Note that values selected here can be overwritten by content or additional content (see other configuration properties) using the same ticket key.
content) The values are interpreted as follows:
- The value
@usernamerefers to the authentee's name. - The value
@rolesrefers to the authentee's roles. - The value
@all-context-datarefers to all context data of the authentee. If used, all context data entries are stored in the ticket using their own keys. TheticketKey(see other property description) is ignored for this value. Even if this special value is used, selected context data container entries can still be selected by their name (see item below). - All other values are used to reference a value in the context data container of the authentee.
Note that values selected here can be overwritten by additional values (see other configuration property) using the same ticket key.
additionalContent) The values are interpreted as follows:
- The value
@all-additional-valuesrefers to all additional key-value-pairs provided to this plugin. If used, these values are stored in the ticket using their own keys. TheticketKey(see other property description of list elements) is ignored for this value. Even if this special value is used, selected additional values can still be selected by their name (see item below). - All other values are used to reference single additional value in the list of additional key-value-pairs.
Note that values selected here can overwrite values from the context data container of the authentee (see other configuration property) using the same ticket key.
Values available for identity propagation: The following values are available for identity propagation, if the corresponding feature is licensed and configured.
Values available in REST login identity propagation, when using the 'REST Identity Propagation' plugin:
- AUTH_TIMESTAMP: the time of authentication
- AUTH_TOKEN_ID: the auth token id as used for transaction approval
- REPRESENTER_ID: the representer's ID, as used for user representation
- AUTH_TIMESTAMP: the time of authentication
- AUTH_TOKEN_ID: the auth token id as used for transaction approval
- AUTH_PLUGIN: the authentication plugin identifier
- LANG: the user's language as used in the login forms
- GSID: the global session identifier
- CLIENT_IP: the client's IP address
- GEOLOCATION_CITY: the geolocation city
- GEOLOCATION_CONTINENT_CODE: the geolocation continent code
- GEOLOCATION_COUNTRY_CODE: the geolocation country code
- GEOLOCATION_LATITUDE: the geolocation latitude
- GEOLOCATION_LONGITUDE: the geolocation longitude
- GEOLOCATION_SUBDIVISION_CODE: the geolocation subdivision code
- GEOLOCATION_TIMEZONE: the geolocation timezone
- GEOLOCATION_ZIP: the geolocation zip
- REPRESENTER_ID: the representer's ID, as used for user representation
- OPENID_CONNECT_ID_TOKEN: the OpenID Connect ID Token that may have been used for the authentication.
- OAUTH2_ACCESS_TOKEN: the OAuth 2.0 or OpenID Connect Access Token that may have been used for the authentication.
validityMillis)
type: MappingTicketService
id: MappingTicketService-xxxxxx
displayName:
comment:
properties:
additionalContent:
constantContent:
content:
validityMillis: 28800000