← Back to plugin index

App Device Used For Login Unless Last App Device

Description
This plugin returns the ID of the Airlock 2FA App device which has been used for login in an authentication flow of the current user session.
This provider returns nothing in case the login device is the only App device of the user or the login device is not an App device, e.g. Hardware device.

In case no Airlock 2FA account is associated with the current user, no device IDs are returned.

Note: This plugin should only be used in authentication and protected self-service flows since the other flows do not contain information on the last device used for login.

Use case: This plugin is designed to facilitate the secure migration of users from the Airlock 2FA app to either an alternative 2FA app or a new business app that includes built-in two-factor authentication using the Futurae Mobile SDK (One App solution). In contrast to the 'All Devices Except Registered In Flow' plugin, this plugin does not delete all old tokens during a migration but only the one used in this session. This is beneficial when a user has multiple devices, and you want to avoid unintended deletions that could disrupt access from other devices.
For this use case, the plugin should be used with an 'Airlock 2FA Delete Devices Step' which is configured after the step activating the new Airlock 2FA device.

Type name
Airlock2FALoginDeviceUnlessLastDeviceIdProvider
Class
com.airlock.iam.flow.shared.application.configuration.airlock2fa.provider.Airlock2FALoginDeviceUnlessLastDeviceIdProviderConfig
May be used by
License-Tags
Airlock2FA
Properties
Respect Cooldown Period (respectCooldownPeriod)
Description

If enabled, devices in cooldown are never returned. Consequently, if the login device is in cooldown or if there is only one device which is not in cooldown, no devices are returned.

Attributes
Boolean
Optional
Default value
false
Airlock 2FA Settings (airlock2FASettings)
Description
Settings of Airlock 2FA.
Attributes
Plugin-Link
Mandatory
Assignable plugins
YAML Template (with default values)

type: Airlock2FALoginDeviceUnlessLastDeviceIdProvider
id: Airlock2FALoginDeviceUnlessLastDeviceIdProvider-xxxxxx
displayName: 
comment: 
properties:
  airlock2FASettings:
  respectCooldownPeriod: false