Gateway Session Terminator Subscriber (Loginapp)
This event subscriber terminates a user's Airlock Gateway sessions. Upon an event trigger, the plugin contacts one or more Airlock Gateways via their REST APIs, terminating all sessions, optionally excluding the current user's active session. In clustered gateway deployments, it is sufficient to contact a single gateway node to invalidate the user’s sessions across the cluster.
For consistency, consider subscribing to the same events used by the 'Gateway Session Terminator Subscriber (Adminapp)'.
Prerequisites:
- The Gateway Audit Token must be configured to contain only the username
- IAM must be able to open HTTP(S) connections to the Airlock Gateways. This may require changes to your network topology.
Security Advisory: Certain events (e.g., “Generic Step Result With Identified User”) can be triggered without an authenticated user session. Under Denial-of-Service conditions, such events may result in unintended session terminations and should therefore be selected with caution.
gatewayRestApiConnections) keepCurrentUserSession) event)
type: LoginappGatewaySessionTerminatorEventSubscriber
id: LoginappGatewaySessionTerminatorEventSubscriber-xxxxxx
displayName:
comment:
properties:
event:
gatewayRestApiConnections:
keepCurrentUserSession: true