← Back to plugin index

Gateway Session Terminator Subscriber (Loginapp)

Description

This event subscriber terminates a user's Airlock Gateway sessions. Upon an event trigger, the plugin contacts one or more Airlock Gateways via their REST APIs, terminating all sessions, optionally excluding the current user's active session. In clustered gateway deployments, it is sufficient to contact a single gateway node to invalidate the user’s sessions across the cluster.

For consistency, consider subscribing to the same events used by the 'Gateway Session Terminator Subscriber (Adminapp)'.

Prerequisites:

  • The Gateway Audit Token must be configured to contain only the username
  • IAM must be able to open HTTP(S) connections to the Airlock Gateways. This may require changes to your network topology.

Security Advisory: Certain events (e.g., “Generic Step Result With Identified User”) can be triggered without an authenticated user session. Under Denial-of-Service conditions, such events may result in unintended session terminations and should therefore be selected with caution.

Type name
LoginappGatewaySessionTerminatorEventSubscriber
Class
com.airlock.iam.login.application.configuration.event.LoginappGatewaySessionTerminatorEventSubscriberConfig
May be used by
Properties
Gateway REST APIs (gatewayRestApiConnections)
Description
The Airlock Gateway REST APIs that are invoked to terminate the user's sessions.
Attributes
Plugin-List
Mandatory
Assignable plugins
Keep Current User Session (keepCurrentUserSession)
Description
If enabled, the user's currently active session is not terminated. For example, if this event subscriber listens for password changes and this flag is enabled, a user's active session will not be terminated when they change their own password.
Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)

type: LoginappGatewaySessionTerminatorEventSubscriber
id: LoginappGatewaySessionTerminatorEventSubscriber-xxxxxx
displayName: 
comment: 
properties:
  event:
  gatewayRestApiConnections:
  keepCurrentUserSession: true