Loginapp
authenticationFlows) selfRegFlows) publicSelfServiceFlows) protectedSelfServices) ui) userStore) The user store for the REST API.
Important: A user store is almost always required unless there are only persistency-less authentication flows configured.
securitySettings) languageSettings) eventSettings) maintenanceMessages) gatewaySettings) If no settings are configured, extra information from the reverse proxy will not be available and it may be harder to correlate log messages that are written to different log files.
sessionIdleTimeout) sessionLifetime) samlSettings) oAuth2SSOSettings) oAuth2ASSettings) Configuration for OAuth 2.0 / OpenID Connect SSO (Airlock IAM as Authorization Server (AS)).
techClientRegistration) oneShotAuthentication) rest) Configures session-less endpoints of the Loginapp REST API. These endpoints require authentication credentials attached to each request, but don't require previous authentication with a flow.
These REST endpoints begin with the resource path /<loginapp-uri>/rest/protected/my/.
For most of the session-less protected REST APIs, there is a corresponding flow-based API in the protected self-service REST APIs. Whenever possible, prefer the flow-based variant over the session-less configured here.
geolocationProvider) stateRepository) Defines where IAM stores all state. As long as only one instance of IAM is running (no horizontal scaling), the in-memory repository can be used.
If session context retention is used, this plugin may only be configured in the default context.
contextExtractor) Specifies how a context is to be extracted from a request.
Depending on what context retention policy is configured, this value might then retained e.g. for the duration of the request, or the duration of the session. Additionally, depending on what retention policy is used, this extractor might be evaluated e.g. for each request, or once per session.
contextRetentionPolicy) Specifies how contexts are retained.
This property defines when the context extractor is evaluated, and how long the resulting value is retained. Depending on the retention policy, the context extractor may be e.g. evaluated once per request, or once per session.
crontoAppCommunication) Cronto Handler to handle direct communication from the Cronto apps. This handler is used by the technical Cronto servlets that handle requests to approve push or online validation messages, return the transaction list or handle push notificiation ID registration.
This Cronto Handler is only used if push or online validation are active.
customExtensions) readinessHealthCheckEndpoint) logUserTrailToDatabase) Configures the database settings to use when persisting user trail log entries.
If this value is defined, then all user trail log messages generated by the Loginapp module will additionally be forwarded to the database configured within the referenced repository plugin.
All forwarded log entries are stored inside the table "USER_TRAIL_LOG". Note that setting this value does not disable writing log messages to the Loginapp log file.
correlationIdSettings) Defines settings for correlation ID transfer and logging inside the Loginapp module.
If undefined, no correlation ID will be logged for this module.
deviceUsageRepositoryConfig) jwksSettings) Enables a JWKS endpoint for all keys used in Loginapp, if configured.
The JWKS endpoint URL is /<loginapp-uri>/rest/public/jwks/
type: Loginapp
id: Loginapp-xxxxxx
displayName:
comment:
properties:
authenticationFlows:
contextExtractor:
contextRetentionPolicy:
correlationIdSettings:
crontoAppCommunication:
customExtensions:
deviceUsageRepositoryConfig:
eventSettings:
gatewaySettings:
geolocationProvider:
jwksSettings:
languageSettings:
logUserTrailToDatabase:
maintenanceMessages:
oAuth2ASSettings:
oAuth2SSOSettings:
oneShotAuthentication:
protectedSelfServices:
publicSelfServiceFlows:
readinessHealthCheckEndpoint:
rest:
samlSettings:
securitySettings:
selfRegFlows:
sessionIdleTimeout: 30m
sessionLifetime: 8h
stateRepository:
techClientRegistration:
ui:
userStore: