← Back to plugin index

Loginapp

Description
Configures the Loginapp component.
Type name
Loginapp
Class
com.airlock.iam.login.app.misc.configuration.Loginapp
Properties
Applications and Authentication (authenticationFlows)
Description
Settings for target applications with authentication and authorization flows. This property configures the behavior of the REST endpoints. To enable the user interface (single-page application), configure corresponding "UI Settings"
Attributes
Plugin-Link
Optional
Assignable plugins
Self-Registration (selfRegFlows)
Description
Settings for user self-registration flows. This property configures the behavior of the REST endpoints. To enable the user interface (single-page application), configure corresponding "UI Settings"
Attributes
Plugin-Link
Optional
Assignable plugins
Public Self-Services (publicSelfServiceFlows)
Description
Settings for flow-based public self-service flows. This property configures the behavior of the REST endpoints. To enable the user interface (single-page application), configure corresponding "UI Settings"
Attributes
Plugin-Link
Optional
Assignable plugins
Protected Self-Services (protectedSelfServices)
Description
Settings for protected self-services (flows and token management that are accessible to authenticated users). This property configures the behavior of the REST endpoints. To enable the user interface (single-page application), configure corresponding "UI Settings"
Attributes
Plugin-Link
Optional
Assignable plugins
UI Settings (ui)
Description
User interface settings.
Attributes
Plugin-Link
Optional
Assignable plugins
User Store (userStore)
Description

The user store for the REST API.

Important: A user store is almost always required unless there are only persistency-less authentication flows configured.

Attributes
Plugin-Link
Optional
Assignable plugins
Security Settings (securitySettings)
Description
Loginapp security settings.
Attributes
Plugin-Link
Optional
Assignable plugins
Language Settings (languageSettings)
Description
Configures language settings.
Attributes
Plugin-Link
Optional
Assignable plugins
Event Settings (eventSettings)
Description
Configures handling of events in the Loginapp.
Attributes
Plugin-Link
Optional
Assignable plugins
Maintenance Messages (maintenanceMessages)
Description
Configures settings related to maintenance messages.
Attributes
Plugin-Link
Optional
Assignable plugins
Gateway Settings (gatewaySettings)
Description
Settings regarding an Airlock Gateway or Airlock Microgateway reverse proxy placed in front of Airlock IAM.

If no settings are configured, extra information from the reverse proxy will not be available and it may be harder to correlate log messages that are written to different log files.

Attributes
Plugin-Link
Optional
Assignable plugins
Session Idle Timeout (sessionIdleTimeout)
Description
Session idle timeout for the Loginapp. When IAM is deployed behind an Airlock Gateway (WAF), timeout and lifetime values should always be longer than those maintained by the Gateway.
Attributes
String
Optional
Default value
30m
Example
30m
Example
2h 15m
Session Lifetime (sessionLifetime)
Description
Session lifetime for the Loginapp. Unlike an idle timeout, the lifetime cannot be extended by activity and is always terminated once the lifetime has been reached. When IAM is deployed behind an Airlock Gateway (WAF), timeout and lifetime values should always be longer than those maintained by the Gateway.
Attributes
String
Optional
Default value
8h
Example
4h 30m
Example
8h
SAML Settings (samlSettings)
Description
Defines SAML IdP (identity propagator) and SAML SP (service provider) settings.
Attributes
Plugin-Link
Optional
License-Tags
SamlIdp,SamlSp
Assignable plugins
OAuth 2.0/OIDC Clients (oAuth2SSOSettings)
Description
Configuration for OAuth 2.0 SSO (Airlock IAM as Client).
Attributes
Plugin-Link
Optional
License-Tags
OAuthClient
Assignable plugins
OAuth 2.0/OIDC Authorization Servers (oAuth2ASSettings)
Description

Configuration for OAuth 2.0 / OpenID Connect SSO (Airlock IAM as Authorization Server (AS)).

Attributes
Plugin-Link
Optional
License-Tags
OAuthServer
Assignable plugins
Technical Client Registration (techClientRegistration)
Description
Configures settings to the registration of technical clients.
Attributes
Plugin-Link
Optional
License-Tags
TechClientRegistration
Assignable plugins
One-Shot Authentication (oneShotAuthentication)
Description
Configures the one-shot authentication using Airlock Gateway.
Attributes
Plugin-Link
Optional
Assignable plugins
Session-less REST Endpoints (rest)
Description

Configures session-less endpoints of the Loginapp REST API. These endpoints require authentication credentials attached to each request, but don't require previous authentication with a flow.

These REST endpoints begin with the resource path /<loginapp-uri>/rest/protected/my/.

For most of the session-less protected REST APIs, there is a corresponding flow-based API in the protected self-service REST APIs. Whenever possible, prefer the flow-based variant over the session-less configured here.

Attributes
Plugin-Link
Optional
Assignable plugins
Geolocation Provider (geolocationProvider)
Description
If configured, all IPs are geolocalized to provide additional input for the flow engine about approximate geographical location of the request origin. If a geolocation provider is specified, data is potentially persisted.
Attributes
Plugin-Link
Optional
Assignable plugins
State Repository (stateRepository)
Description

Defines where IAM stores all state. As long as only one instance of IAM is running (no horizontal scaling), the in-memory repository can be used.

If session context retention is used, this plugin may only be configured in the default context.

Attributes
Plugin-Link
Mandatory
Assignable plugins
Context Extractor (contextExtractor)
Description

Specifies how a context is to be extracted from a request.

Depending on what context retention policy is configured, this value might then retained e.g. for the duration of the request, or the duration of the session. Additionally, depending on what retention policy is used, this extractor might be evaluated e.g. for each request, or once per session.

Attributes
Plugin-Link
Optional
Assignable plugins
Context Retention Policy (contextRetentionPolicy)
Description

Specifies how contexts are retained.

This property defines when the context extractor is evaluated, and how long the resulting value is retained. Depending on the retention policy, the context extractor may be e.g. evaluated once per request, or once per session.

Attributes
Plugin-Link
Optional
Assignable plugins
Cronto App Communication (crontoAppCommunication)
Description

Cronto Handler to handle direct communication from the Cronto apps. This handler is used by the technical Cronto servlets that handle requests to approve push or online validation messages, return the transaction list or handle push notificiation ID registration.

This Cronto Handler is only used if push or online validation are active.

Attributes
Plugin-Link
Optional
License-Tags
Cronto
Assignable plugins
Custom Extensions (customExtensions)
Description
Custom extensions for the Loginapp. Allows connecting custom configuration plugins to the IAM Loginapp module.
Attributes
Plugin-List
Optional
Assignable plugins
Readiness Health Check Endpoint (readinessHealthCheckEndpoint)
Description
Readiness health check endpoint for the Loginapp module.
Attributes
Plugin-Link
Optional
Assignable plugins
Log User Trail To Database (logUserTrailToDatabase)
Description

Configures the database settings to use when persisting user trail log entries.

If this value is defined, then all user trail log messages generated by the Loginapp module will additionally be forwarded to the database configured within the referenced repository plugin.

All forwarded log entries are stored inside the table "USER_TRAIL_LOG". Note that setting this value does not disable writing log messages to the Loginapp log file.

Attributes
Plugin-Link
Optional
Assignable plugins
Correlation ID Settings (correlationIdSettings)
Description

Defines settings for correlation ID transfer and logging inside the Loginapp module.

If undefined, no correlation ID will be logged for this module.

Attributes
Plugin-Link
Optional
Assignable plugins
Device Usage Repository Config (deviceUsageRepositoryConfig)
Description
Configures the database settings to use when persisting device usage data. This repository is used by the Device Usage Processor. If not configured, the device usages are not stored and thus no conditions and events based on previous/first device usage can be used.
Attributes
Plugin-Link
Optional
Assignable plugins
JWKS Settings (jwksSettings)
Description

Enables a JWKS endpoint for all keys used in Loginapp, if configured.

The JWKS endpoint URL is /<loginapp-uri>/rest/public/jwks/

Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: Loginapp
id: Loginapp-xxxxxx
displayName: 
comment: 
properties:
  authenticationFlows:
  contextExtractor:
  contextRetentionPolicy:
  correlationIdSettings:
  crontoAppCommunication:
  customExtensions:
  deviceUsageRepositoryConfig:
  eventSettings:
  gatewaySettings:
  geolocationProvider:
  jwksSettings:
  languageSettings:
  logUserTrailToDatabase:
  maintenanceMessages:
  oAuth2ASSettings:
  oAuth2SSOSettings:
  oneShotAuthentication:
  protectedSelfServices:
  publicSelfServiceFlows:
  readinessHealthCheckEndpoint:
  rest:
  samlSettings:
  securitySettings:
  selfRegFlows:
  sessionIdleTimeout: 30m
  sessionLifetime: 8h
  stateRepository:
  techClientRegistration:
  ui:
  userStore: